907f48f3...e07e | Sequential Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Wiper

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xe0c Analysis Target High (Elevated) hgaibc.exe "C:\Users\FD1HVy\Desktop\hgaibc.exe" -
#2 0xf8c Child Process High (Elevated) cmd.exe "C:\WINDOWS\system32\cmd.exe" #1
#4 0x83c Child Process High (Elevated) mode.com mode con cp select=1251 #2
#5 0xe24 Autostart Medium hgaibc.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -
#6 0xe34 Autostart Medium hgaibc.exe "C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -
#7 0xe40 Child Process Medium cmd.exe "C:\WINDOWS\system32\cmd.exe" #5
#10 0xed8 Child Process Medium mode.com mode con cp select=1251 #7
#11 0xf98 Child Process Medium vssadmin.exe vssadmin delete shadows /all /quiet #7
#12 0x2a8 Child Process High (Elevated) hgaibc.exe "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -a #5
#13 0xc40 Child Process High (Elevated) cmd.exe "C:\WINDOWS\system32\cmd.exe" #12
#15 0xbb0 Child Process Medium cmd.exe "C:\WINDOWS\system32\cmd.exe" #5
#17 0x500 Child Process High (Elevated) mode.com mode con cp select=1251 #13
#18 0x4a0 Child Process High (Elevated) vssadmin.exe vssadmin delete shadows /all /quiet #13

Behavior Information - Sequential View

Process #1: hgaibc.exe
37310 0
»
Information Value
ID #1
File Name c:\users\fd1hvy\desktop\hgaibc.exe
Command Line "C:\Users\FD1HVy\Desktop\hgaibc.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:27, Reason: Analysis Target
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:46
OS Process Information
»
Information Value
PID 0xe0c
Parent PID 0x860 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 408
0x DB8
0x F78
0x D78
0x F58
0x A8C
0x D14
0x EF8
0x EFC
0x D24
0x CF4
0x A98
0x D44
0x 58
0x 2E8
0x A34
0x D9C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Relevant Image - 32-bit - False False
Dropped Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\FD1HVy\Desktop\hgaibc.exe 92.50 KB MD5: 5cb48ce239ba5b3ca53eeb45c155b9ee
SHA1: 3cd62251b8d580115dc0913ffd4e071b96000493
SHA256: 907f48f3480d0de1c0fc7a518e31e38f7d2da11fefaef88a5888e89194ace07e
SSDeep: 1536:mBwl+KXpsqN5vlwWYyhY9S4AQI2fKMQf7X5R7q1py3RMkkoA9hX9Jz1:Qw+asqN5aW/hLONffQfL5R7q7k7yh/1
False
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat 416 bytes MD5: 7966c59f048a68e8ba4e6e88c6f3fd5f
SHA1: ec13dabd2c9028ed617319d022a9ef3f39488384
SHA256: b275b7f9f5f74b3ab50478743bbc17ec84a16f89de39f01433048c0a0c75fa7c
SSDeep: 12:8ynAHNEUXdpKpKUW/laqarNUKguXny3sl:lSNNdApKH/laq8LXny3E
False
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 378 bytes MD5: 72a89fbc3ae3555a54d59d3894f50c7e
SHA1: 7669935464029589fb40d2665ef7dfcef1e9b135
SHA256: 20eb1bc39b2fd720b9ec89225dba9a98964009e037ea973120b14de614cc18e4
SSDeep: 6:0RtE0ECLtem0V4OpCx4Ypzya89c6WC2EyySwACtXUPSgu1lw6QGyAER+:0RQAXg4OpCx4YpzXk8rAVJUKguXny3+
False
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: 30eaca111ed5515a5c45fdd995bf111e
SHA1: c375e0ce6bc9b72b5e2dfbd3ef697630c496854c
SHA256: 25ca13c0a640cee0bbc7b60c0e53777e2cb3d5d60a2c7b08703db8929c14c192
SSDeep: 384:lMYrxMMj0AKYbbqIXFJjwVIdyLIcSY/fbn7Enw:hxjAlYlUVyyUqDn7Ew
False
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat 5.71 MB MD5: 68e1b85cb6f7365fbaaa6fdf7af3c6a5
SHA1: f35ab7ed5d6e2756cfdf0d79719835d964c47645
SHA256: da08eeeed28ec19df8cc23c3beaef1066d01b73d5b7237796b17ac98844fde21
SSDeep: 98304:uuEAUjb7BkOKxUKnat45mFe4H5+Ju4JKUYc93iKlOK1U2:e3PBkOK2Knq45mY4H5OMKkKN
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a2bbf31bb88939e21c0d7f429a04f98a
SHA1: 8c1c63b614fd35dc026c92161abd63a7efc83187
SHA256: 4933f64eda641d23bff597464dd477bac1219514deff860ddf3dec4cf46089c3
SSDeep: 48:WlC3Qkd1Jw9wC5fv/Bwla2MWwsg5bHzwylIy3a:WlAbd1xCVy9MWzg5Xw70a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: bb7ac606121e1f8b896ba51b64302d16
SHA1: c003fdc30a9badecf02786bc370dda78e71a0c3c
SHA256: 364c7a1afb2db092d7bdecb194d70970325d8e583de660fbef57c9a7081a70cb
SSDeep: 48:OgyO3rtBJhDeXW/NAGw+oJ4E00Nj3IRBGBQB1lnm0y3a:n3hpCG/6zj4EvNT486a00a
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 4.53 KB MD5: 7babbe7f341ab2ae480064b259b4a653
SHA1: 03ff7b67ae26560b43f463a8be37c06192a062d4
SHA256: b0ddddf21dfeb6dede110625c2bace7a23c7c4b642fa2d9a6d67ca41c831983f
SSDeep: 96:pYJecTh98CeeLSa6Z3ZA0iyKNc90nwo012lftDLM0o:Szh98C2Z3O0idcSwo0ytDg0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.51 KB MD5: 3cd4a37e799fd4a15593e09339e68f05
SHA1: 7ebcc2fc0ae5d4d0bf3e0a079c7e8c753d93af09
SHA256: 33d9f8a3b0fcaaf5bd495ee9f9da39e1dc2b49fb3c3ffdd0e16340b2cf8e3df8
SSDeep: 96:Hfkea/JGjOE8E+Z31jvdJ8Bf90bg9tzrpKHj5C0o:uRGjh+rjUr9tzrWjc0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.43 KB MD5: 1f2a094545f38548d661727ef70992e1
SHA1: f0dd8affa742fa7fba78b6eb1a4f37bd419e5ce1
SHA256: 58050007d320338cae967028d50dbe66263dfbb63eec29077dc665f860d6d731
SSDeep: 96:iZg0rWHyrv2+gOaGcIxr4mXyaslXFt7oLnTxub6ht11SZRLsW0o:4ginu+CGc6xfsFn7untjh4x0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.82 KB MD5: 1b3a39f0d9f7a9c10e329c28a5d1de5e
SHA1: c2b1051ebf14047eb4e29448e974b56fbb9317ba
SHA256: dd367672e5fe8d17795133a91dc884409a411eb8313f693a43d3f57848192ecc
SSDeep: 192:+0iBiZzxAvqZRpL5jCmB14SlgY5cWi/7nzuT6weseJv9JQ0o:+0zqI5+mB6WiTvwesCvr3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.15 KB MD5: 4dbb00daeabb094c73440f2cc82627e9
SHA1: 799e971e56bae75d75392c1b4feecc0ae7f81d04
SHA256: f3567760631ce992d33c2a47dcd5d07ee691bce932ec28f4ecc7b2568b7f4557
SSDeep: 192:Oqk/ZFQF1aNZpKXSpewzFBy5JXPxVuH8iX2gCRru7FNtqLWkyq2FoDqtyO5oNBww:ONo3a9KCpeyaJXPmGVRaPtqL/yq2iDA2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.67 KB MD5: fe2b70c8913b3cf92094d995ef66a601
SHA1: 512e2f7132772c934433c65d86a2eb72d533650b
SHA256: 99bbbfeebf99bf906ba3277c5c1e08d3c771a74b6c1f563292cc3d00ef04142f
SSDeep: 48:gie2cNM7//EbOVM09Ng2o6SddWDtdz6WhADy3o:eRw/yOL9Ov6SkdBhAD0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.61 KB MD5: 5e53faa479d9897a32b44e5d79ba3e62
SHA1: c763ae03a0a8a732ea634fe61a277a3f6e20d080
SHA256: ae2bf4502dc1bd931e41479560e609b0e77b9b0d49355d9907ce7dcc8900ed34
SSDeep: 192:au9ItfNJhRe6TGMqeYV2xdKdw/e6LoAxReMCXSG1WNzHO0Zixyy2Q0o:j9Itf9Tl/YV2xdKdtEehXb1WzPZixyyx
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.68 KB MD5: b4a1b9e2a374b1882e80a1c7687c0b5a
SHA1: 3bc5ea59767d081daf7e9d42fa6bd9a7f2ceff7f
SHA256: c55409deaf5ea12f7a490cd2135b4b586fbbdde5d94a2eab26712e7ab3e601a4
SSDeep: 96:q43rWDgoE+dX996KZI0zX0uPfk6FZUl59wtKjho6dLqQE1LY2j7mpOkUI3D7UG/x:q4bgfT9T20zdk6FZUl5t1RVE1fmpOkj/
False
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: f936d2e011cebf2b2c30c2c86f9a4c63
SHA1: c8f3783725f54c3efd8445f57d536921aa7d8363
SHA256: c976a7a2c136307235b5072b7960d59ef6cfacd4478e562106918e247d0c9a95
SSDeep: 1536:+GFuHjTsryxfDWGvFNPOm029/tkk7iKPlV4wChXfkBcF6CIwxys5:+GUHjTsrGJdRR029ukDPslhXUA6Bw0q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.51 KB MD5: dcb2be5a7d569ff1302d982839cc20a5
SHA1: 44ed44e155ba59b03c322391a2357b9546752829
SHA256: 6d144adccfbd729363e9118774b0ed8a8f9e0df2af8649361f1b1511b1d93889
SSDeep: 48:fIAAIWhXueUulbr+P0oMB7Xthp0Mud3RsaBySuTg+KeJ8DuLAsn+Tvy3o:fIAQITLcp9hUdmNS+UGQuLZn+Tv0o
False
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: 08e06f44ab1532b08898d5ef3c714c25
SHA1: 8c83f4facae3014a8887fb13786a698aeb2e7233
SHA256: 41b54a1dd185c43bd241a3bf833ebfd87553b386d7785881f6ab2c1d307db7fa
SSDeep: 1536:vnuY4y7mkMd1CnJkp/BKTSb+2xeRKm1++089T+n:vuYFmJ1qJ8BKTe3erY+0Q+n
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 22.23 KB MD5: 658089ea6ddf2c23a5aef5dc89476d62
SHA1: 4e7f45c2f155e85f8e05674f5bc89721ba2d7066
SHA256: e34cb9e41458d3313b85ab4031c52ab721c569edcea855441e85bc02252bad34
SSDeep: 384:B6Sak8HSIC3iiKjHIAG/JBS+Whx43QAjXQKyCJOl99PRDoP3mBE6OafF98YgOo:B6SIfiKj5G/4x4AAjAMOza3wVO6FiYgh
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.01 KB MD5: 0752dfe5f73c92b7866e1e9284550dc7
SHA1: a606d617164219b1ced8ee5dc45aa886828eef40
SHA256: df700caa020934e1594702f11a809f21d8a77bdde4dcff21540b6ec5273169e8
SSDeep: 24:uYAcyn3VfdkzoDFSA08dZiFWwZ2awt989GFfYHXny3o:u3cynlfSzoDn086JZ6989GBcy3o
False
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 566 bytes MD5: 81e59b1bd54d7e11bfadc45593a71cbe
SHA1: deebcfe71c324ac1d23b1c8dbba5687cb6866f01
SHA256: 764a556198f0ca2832f055e58a5342ad16ce93e4df977363f3231b6a5169ab89
SSDeep: 12:hoiePL6I0DxK+oXooUnwAtKHgS7tniFH8lxxarrRgoQkNKyXFd6if1GDrpo/:hoix9DxJfoWbTS7tiFH8l38DvNFXrjE6
False
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 852 bytes MD5: 627229317709a4231acb289e518c9762
SHA1: ddf28a623867c5f8d1219bba628edf36d426ee2a
SHA256: 65133525809563f0487a7599abd1ba80ee7c7b166e7963d55fc799aa49a3162b
SSDeep: 24:RCqX3jvZfCT8yXnWW9JsblMP2HuBfP0xeH8l38FR0NFXrjEDc:DpS7XB9J1L8lMFS1rIo
False
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 378 bytes MD5: 1e3695380fc868852817edcdba07a81f
SHA1: feb9d88cf95c5ecce0e09ad6e98868a807404e92
SHA256: 14892b618d9892d0a7d8528e16e11236e7821cca46a354f82ec188ee5f7e0cfb
SSDeep: 6:Gngyxf9bnt1cjd5KjPi2IlK6WC2EyySiEYQHsD/kXUPSgu1lw6QGyAER+:45tuH8r3NMYUKguXny3+
False
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.09 KB MD5: cdc87eee806bb139179a9f3cb2bc09b3
SHA1: 8ccaf9e0af643295869120aa03573ec34eea874c
SHA256: ee753269e4e43b591376ec142ace726279df0e9c7ce9a00cfe373be28bfcbac2
SSDeep: 384:Xx9Htb0Opv6IeglbuqXkQo5VgiqwdCCpAEc0l3ohq:hnQO96IegljXkpVgiqwIwAEN2A
False
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: d86a3934b97610fd1dbac10156dea797
SHA1: 5646e2652f56a3273fdbee23f39b099b74d68e60
SHA256: 92a6c798dec994a50fc7a5acb66a7e81160d1a9e309b0e5c04095229fa3c2edf
SSDeep: 384:VJHz6LpU/1Nl/SgHjSCvX/Iyfa4V0xZI5q+3e/a:/yo1Xfvv76x0q+3z
False
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 2abef858b47bf900e2b41989d69cf36b
SHA1: 4eb4c077cc065b24d4004683ea7f6d4a7e96f6a9
SHA256: d8ab5bbea5b9202e6437698d9d7f8fc39338666570ee45e198af9e9dcd81d612
SSDeep: 384:EPWBDqrXKsbawpw+ionju0X+DoXo/KWX7OlrV62Lyi89EfrdxNFtu4s:WWBD0KsbJJiyi0WLOlZLyi8KrNFtu5
False
C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat 314 bytes MD5: ee30ec4e00e595ba9c769b092a8ec363
SHA1: 25905bba7673d41912e422938f239be992e0f393
SHA256: afa30c0f3be410444f23b67dff40ed9245495ccfedc3fa2a620bb34df9d53711
SSDeep: 6:OqWi17Q/8PHDQlSaXxaEyySO47EqOzINWrZMxNFV36if1GDrp5C3:OqZU/8vraXxarhkkNKyXFd6if1GDrps
False
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 0b2583bb3625b330d8e48fb0bec9ab28
SHA1: d00faf2e12d4a01841edd8ed4a7ddf9d81b7072a
SHA256: 2854bab655d5363874ca8c653a1e8a303944776da3769eee4f60be0584469de1
SSDeep: 384:dndYv+bZt9k4/KCRahl+GkcCcoflNtBnnqKmqXDIKS742HMJHK:dGv+zSoPAQVNn6qTPSzHSq
False
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 19.09 KB MD5: b76aab9244df2148bdc05601a284b9da
SHA1: 6109b3206e86bc61b03a388bbb362b4bc3ccb6c7
SHA256: 6a3472aea2159d49806795d6918d3b2c0e9eb38c5a9555a590639b36801f6048
SSDeep: 192:3wMauiLPe3NEdDVbYkDo6q3xoZ34n0Q/F+xvDwNIOJ1VparivaPEtNX9YK8OZ/JV:g9zsqdqkDOOE0C4xOJFrtDJUxkS9bnK5
False
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[idecryptyourdata@cock.li].bat 140.95 KB MD5: 887bcde435102c501e9311d6633c8f2b
SHA1: d51d1af357f861d6a03c1f6e1a2eea2b733b4319
SHA256: 0eece7b90e566d2ddc14ea9a3424fc648c22bf3cdd4657026c69ae52c9e222a9
SSDeep: 3072:eUQdUi9zYD5lDSzTnKzUCMGM4VlvnebYGRhBZsT5vLIT4i4VilXOj:eUQdUi9zs5lDIPCMv4VlvnebYGRaVvLb
False
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 7.61 KB MD5: 02bbf5c4af24cfaa729130a13df641df
SHA1: 503489bfaa5ccfc6c9dd4ef2369132e4181d8d40
SHA256: 2b50203b193306d2c53935fb980adbbdd6607b787cf4aa2fef361d7e0bfd5804
SSDeep: 192:DlPZrx+JV4PNQhxR5RY03Qo+lRYNZuMsyX5UxlogiWET0Q:9ZNQV4PWffRY03QINdX5UUgiTQQ
False
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat 320 bytes MD5: 14ebff8b9c9f0ebd29503daa61cb536d
SHA1: f42b2e1890f10553e4bbe1fca0257d681e6f987f
SHA256: 47fb8c57b586cda49964e995f35667e6f72fb9217e0a1bcec5cbdf0b5d179387
SSDeep: 6:09Tod41FlUel1DmRH8lD7gTcEyySYyjoWXUPSgu1lw6QGyAER0:0RoG9/1UH8lITcroyj7UKguXny30
False
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat 41.97 KB MD5: 02200f8502e18db40d31c56d2bc141ad
SHA1: e38b060d2ceda0154cc76c605f77f7920f27ef59
SHA256: 9a258b6be923d71eb5368f2814620b3caa556d7f46d1d834b6ac01f6728a1a11
SSDeep: 768:80ZLXYuRKXlYzSD1pgEOwtnPpT3rHpEuCAjfODnKidFLi/umw1evPr1OW8NO6FHa:7LoUeYziohGnPpT3rdjfAnKidFe/0Qgm
False
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.39 KB MD5: 956e6ed5565645d957262188e9617078
SHA1: e64beb8b1c33033e9b85031dc58d24504af69872
SHA256: e7e01988a7960e71ed477260c4669490e4ccca0d6452d0a78312676748b7c332
SSDeep: 192:qgDQm2vI6pHggZfHtj02/4QFIrmoLrYJRc0Q:qQQaOrbP/HISJRTQ
False
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.65 KB MD5: 24b41cf398eecbc9ebfa9580987fd00f
SHA1: 8a7083ef43e90c09a30583819ee1049b3e774153
SHA256: fa76b1be78e1af1eb699d05ef467d2e7e034d71b94f4cbef5245e19fc1cda2c8
SSDeep: 1536:U5L8hCn0K+zUmr1JImKW37Dg6vA9Qnwpe2EMsmth:U5L8hCh/01737DtJA
False
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 72.72 KB MD5: 11ddb0d2ce7ef60b632a3eca704dac53
SHA1: ef1c68e56aa264aee7dbd6f5a4d710d6e8737105
SHA256: 71358b152eeecac2a53cb284c9bdcd50f603ffb6aed2cbd41fb77f939f242766
SSDeep: 1536:utbtuw89AhI3ystsKZaga5p8FQamS7xzBArK22c/frIApAVL/fQQBOTo:G9QAiisXZagGp8FJFF6KBgfrICAVDfQi
False
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.32 KB MD5: f4a8a3a384505359927cfa3a1cefff54
SHA1: eb87fbf3bda51f8fc2d24088bb6108430f7079b5
SHA256: 8c42462c961f368bbb4c44224e1b5c577c4fb83e2fcef2d11ed534b3bdc8d616
SSDeep: 1536:WCfXbc4Y0U2z7rGlnl1IHFJTX0KVLmoAu73qmKvRawa+lW7k7cXzl2eq:vLVYZ7IHFJTXZLmovLl2xlbwXEeq
False
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.47 KB MD5: fd74695ec1fabfe2d4f11099f7897228
SHA1: 75b35a55707a984fa0edca200778fc734462e28d
SHA256: 35cc276f60ab86a6d4caa32ec11a3feab13df36fe4765dd87f615573181e9c30
SSDeep: 96:rlY82a+10hLmWXVp/F2slRflUtNFm0x5cJpY0Q:rd2a20NVkoRj0xF0Q
False
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 76.18 KB MD5: a5432df8906deb930b5ded09da4c6a24
SHA1: 6ee6c5c26405afc7aa4d21fd0f93edcddaac87b6
SHA256: 700ab610649e7e27689c584474c1c5cef89901e5e53d20cd13691500fd796c8a
SSDeep: 1536:TFUm1rnCz5tS2azG/nHchgihcLQmGQumczUTxd83W8955fK/U:TmAoxaq/HcKiNNWY3W8vfn
False
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.86 KB MD5: 0488fc9eb46148b493ea591a36c83204
SHA1: 598f9bdd65ad1497c84fe8a3ec3cd06503d4790c
SHA256: d30b605d0449fce04cc1343c2721edfc850513738f619aa1a7cfd091b574d6c9
SSDeep: 96:Oui3JjbP6ppWDjyc1NanFG4XuAm6Jm0H7KaMsOUu1M/GX0Q:OuucSusquAFmCKa8N0Q
False
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 80.66 KB MD5: 68b1e47b1f708f865c980b64ee86647b
SHA1: b8084a73be8172845d4aa77e0866bf95b14061e3
SHA256: f2c7e7f25e7208d6f23efb738c9c374d71acf5167ffbd9b9b9486b952653a292
SSDeep: 1536:EIKq3dPSbaLJIGcOTnmapjJ/CnQwYYHPU0CsVUtN4va/0PkJSEB:ETqob9GcO7Fw7Ss6tj+sB
False
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat 6.14 KB MD5: 03ff9a3c84c71c134d89e1ee682909e8
SHA1: 4ea6ac5a5be2d13fb46dadb78af6be7102a084d3
SHA256: f367b2a96fa1cfee411fe08ff23568170f3dcfb386f71ffc08dcdf2545102404
SSDeep: 96:f7WAcKnPYJaZBC8zAlSc670pDG4NnJAYIZr4As7TPnMW4/dD4YN8WedWPVDuZZ8u:TnuUSiA/67MNrIZ8V3ulHtDud0g
False
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 1f465f9994178a358bfd7e8d139cd915
SHA1: 4ffe645c03a552b08ad4242a5110cefe6574a841
SHA256: 64b919f8206aaed1bad37e94853f92c371a730a8aea057568219305c47a28084
SSDeep: 384:vUFToXQbRePfY4yUgwiV/SP+aagLntA8YAbkaDyJcZS6eoowOzv:vsoXaePfY4OwSSp7tZd4uyus3opOb
False
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 16.59 KB MD5: 14b410989e8a7aaf20550267bd2a48c8
SHA1: db5e9a77df80ab78809f9dd8252184d5055b03f3
SHA256: 232976da126a3cee50666660a3274e7cc7c6ad39166a80e8533d3a99893b251b
SSDeep: 384:ylylcAwL3dqjs//axc9CLkMrp28xHsoI2/pbGrTMiZqQOYd:ylyc7pcs/6clC4azI+AYiZqPo
False
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: dfdf12aceba3588810afba8f50631a41
SHA1: bce38528143c8053df329f3da2dbaaeed6f8916f
SHA256: 6661b3e70eb05704907f19abebd6bc0e94f53bba86b51e310f0ea1d70aed62a2
SSDeep: 384:J7exjjc6IxC+3F0Q67bqPVM4Zk6uCEHyn0PtQT9sHySjf5zmP//6ZdWsXMjspka5:teFo6ICKP67bt4ZkDYn0qT9EyAOeFXMa
False
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 216ef4bdc6b77456f6e01e9993c8d3fd
SHA1: 40006f8bdd8b0133efbca76e7d4c42a7d5eaf69b
SHA256: 2bca198d1212c111f7580378ee348edd66cb694dfde412d7fafa684621e4844b
SSDeep: 384:1Y60Ixt/UrZk6UgJp/Sh+08OVAo6E1DegzFglXVLt:1DlUrFUGn08OCo6ERF0VZ
False
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 15.59 KB MD5: f7c440243acfadc56f56c5cbe76cbd5d
SHA1: d6c887cf3c8039481101ffa609ffa0ba44621b15
SHA256: c847b094aeadb27bd21893503b85ec859c046902a4da92741ca17940ab32fbbf
SSDeep: 192:80xQoPfFbmhsQB34m5n4A2CUFufBRaVczYShq/SyRhMvsGIQdysiDFjBEFsrxIs1:E0yVppUFOBQCh+SwXDgk1EurxsvTg
False
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 8.89 KB MD5: 381e95b4377193ba81346fc0964b76ca
SHA1: 89185241c95fce905192e14babd0acc796d06ab7
SHA256: 24d0212d7dd856e8ef074ecdd1934dd73d1b1b2bff634c6a268d6425a2cbf7af
SSDeep: 192:tjvLuaCnGFymQcmPDLLjYXStgNyMCw206S0Fd25RwYsUtaZ8xk0Q:tjvLP8NPffYogNyMCVLZd25RIZCLQ
False
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 15.09 KB MD5: a39dc270015f9db44b250d8729a2ffa7
SHA1: 80a8bf696c0f80c1d11cf76f7e6836385c1810e2
SHA256: 00edd3f4be782d46fe3f4e0b80c6e97a6314d46417a40e37535cda2a948b560b
SSDeep: 384:hLT0etnCA75z/wp6IANwiK2tlRxkY7sDl7TB4BDiDQ+46JtVAOlh:hLTnZdwp6pu+xyBA+EziVAOv
False
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 84.51 KB MD5: 9559316b94fe12382acb3449426a029c
SHA1: f217906638e6250afee8a25ad077241c2953708b
SHA256: 443a757d5cb295158e2115fa08e645c4faf326bc984955bc0677b08d76392f8e
SSDeep: 1536:/rgpfggYwwZZ4iQDOa61wrvnC6b0tOFOP8/zOpRI5dRFlmcj0e+zBm:/MpfggXAZ4gwbb0t4OP0z95X4Bm
False
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.35 KB MD5: 0846a91b271f08f8de67447ce5d00968
SHA1: ec0aca83632b197c8005a1aa8d9540fe7e9628e4
SHA256: 0f3b580d37a5880bf332532874c005a3265eeefa357f45b0ce8edecc963b4473
SSDeep: 96:dG79b1V+2EPU668bwbKg+OoIKqfVhaDi0Q:dk9buhU7tbaO59ha+0Q
False
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.68 KB MD5: c7583bd7457abbb75f1817d1852e6f31
SHA1: aed0ccb86a1e65a0d6af4d1c2d709d670ff43baa
SHA256: a8c2442c2a9fa1f82a9d324e8b60d7f4d05d050454fb186712f23d5733e96dcc
SSDeep: 1536:sWc+Ancnpumoz2kP37GYHqz1/e+GrBBn58Wvl5fVAg7BjZty/RS8+NBI:sWc9SqzcPArV//7dVXywDN+
False
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.85 KB MD5: 02fab8934ee5f3beb4ad0838b9ee9e2c
SHA1: 99eca6a9d61d86bd49e393861986e5e7633f0e72
SHA256: fc702139b1bb906a8cf697db03b0b44587e9cbba340d4707647c52ad2d864fdf
SSDeep: 96:LzVMaUO9h/i9FYyRUeiPg4XLxztW5o9eA1gVz6/l9uQPZ0Q:Lmoa9F0tPdztWpRz6fn0Q
False
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.09 KB MD5: 8d65803915f5418bb2c725b5dd8f3a12
SHA1: 0858756145c9a0829e71f5428cbb700241c79eda
SHA256: e20f02c36207591db9b1108730484b1147f795ef0f6002f56b0d4bf5fa2e21c0
SSDeep: 384:0IpR2dUI4c5lrR0dgo8oQlb9Swt5CnjvBhtGiUER4XtSg3o:0KsgyJRAgoJu9SgsnLBvRYog4
False
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 73f022fd834d39f6c0ede5143867453c
SHA1: c2623fef2e1c5d099f534ee29785a038129c729c
SHA256: 7ce4f65692a02bb795427a30b084bb3d4664e4a187acf6767ef03c92eabaf233
SSDeep: 384:7dxyGpWVnqbZjdirnaDw0GVjXqck9hZ425J82U0dfO14iIS8S:BxyGQVn2ZqSGV84yJ82LdfKDf
False
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: aa29c394ebeec30c35d9034bde1d3016
SHA1: bfc7f2fc2a5f647f869a6120ae34827dbf2af8fb
SHA256: 0e036da7606229e63ab04b6d2f0a0feddc273cf16aefc53362f87c172e8052a0
SSDeep: 384:Idqc3wpuE6Htqf0iS5grRn/zzWPF3fzQ0NajHqqVFCr+rXoSpb3xl:Ioc1E6HtoS8RLzWfzQ0YTCrCXoGn
False
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.68 KB MD5: 354f996331246c4ae2ab012ec89338b5
SHA1: 6923057910d2acee209989987986aa971c6528fa
SHA256: 015349aea24d711656b003d65b0cf714abfe2e51e724a1b86b0f634e288fd87e
SSDeep: 96:o5+JNN9X3WTKtDFPDZ/XY2mA7meBWrgfcAv0Q:o5EN/Y8PDZ/o9emKWMEs0Q
False
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: d868bd1697c42e1a252242289367e4db
SHA1: 18d4207064e19ac2dd35278e4ab84210baa08bbe
SHA256: c6b3f6425b729e74dc5f761e16025caf48b33336cb3e9b9e0193853cdb5454c7
SSDeep: 384:ZJ2R9MkT5xQylYbzsshulIq1EE2earRcsKaHzcgGgc+x/6llc:iRXPQlU3oL1dKaHAEF
False
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.46 KB MD5: 3dc5653b99f6fddf2b590f32798058de
SHA1: 910ed6e1e8e91e5946a0d85835f263097cade3ed
SHA256: 603b6865bfe60f6181c52fb808bd77120c674d9b82533d60a9de8e018618517a
SSDeep: 1536:hMuzc4ojNr9zZLY7l/YAdFNbBPhpIhyhyDmZ2ZxQ3mUUmMoMF7ZxP/5:GmaNrPy/XvBDtEDmIZ6PMoa7p
False
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.93 KB MD5: 71d77aca14520ca21a4d5d4292d5d8f0
SHA1: 438673812275b0a1cebb0fac69863b4d4716e284
SHA256: ebd786cb62f8c8f5c0e94d7556acef3273417854de8b955f4f4e3bc35eadc3bb
SSDeep: 192:nYCOKQMhd51LL/6jzXKKCEfNM9DERjbUl0Q:n13QMh9LL/qzsUWERjbUiQ
False
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 81.27 KB MD5: 96934984af63b196ab2263d7e5727fa9
SHA1: e15285466020271db2b8edcfe774c8f9f5098494
SHA256: 8c64d7b59853529d714e893dcccf70441753270ac8f556d80b0d77eb31056b26
SSDeep: 1536:SNbJ4QcknQC2uasmaUW8svVQS3+/Uboi3c7rxcO4Wg5qRidvlvn+YOznL:A4Q/QluasmaUW8KppoisnVQqwnfOzL
False
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 4fc9e3d699d7ae3a5ae4c30c070e2604
SHA1: 81fd857b8e22f410bb5a9c171f0e700fc1533c0d
SHA256: 7349035bb72b51a36156c7505122a878b40683dece9c4a8be82f12536005a8ee
SSDeep: 384:jPWk0G8YySMwKnjCJmLrOMl71rv6NB4sGSzVyPlDYQEU/t+Yw:zWk0rJpvPOeUHzAP1YQEJ
False
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 1bc70d14df9fdf8fa2d77f83de2a7b21
SHA1: dd53a96c94017f65871db4aebda27b03170e80db
SHA256: dcc81cd5b6a21d5aebd48930d20d780bc0064c364d5ea1ee516bdabbd89e07ca
SSDeep: 384:6MBbDJkp5CnDkWD4uLJRuIBBHxD1m/qaAwGsV+/Aupvg6er70ZyYpn/l:F5kp8Y8zuIL6HzGt/D/vh
False
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 70.63 KB MD5: cf757704dc735c1d335e30fbf76c0cc3
SHA1: 1e12fc6b27593bd08d531404670ec44ed4f11a02
SHA256: 887d4e5e572378fb5edef09f463ba0241fc25757ba4f0967370134801fe4989a
SSDeep: 1536:27BKz/vaiZ0zI04WfSXoE9LXagohn/a9Uq3uevNvmiE3AeS12ZcKsVnbPn:2FeZTSwX9+Xh/AVvNvm3wz12ZcKmbv
False
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.38 KB MD5: 744288cccbd96f209111490816b7df76
SHA1: 80a377edd78582cf85f8a0443041c6a3ce66a5a9
SHA256: bacbd74e34097b3a6000e025e5c6df26ff5ec0562524f422e6cba85f8946f865
SSDeep: 96:QpgLdyjNywE8iL4lrUFgRwa0nF/0et8ycH+Bn2g7JySa0Q:QpZ+CUFgRwa0nFKycH+BnHG0Q
False
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 84.66 KB MD5: 2656f1133f03e9d238ce5ef5ccad97be
SHA1: bb4ede7ea31a7ee4075bfb934292853c46443730
SHA256: 64319675b0892a04541198461d82c133425f5883516e30ea5f01c70844c2311c
SSDeep: 1536:C/30RZVN/VOXSBOKMHjAjw19DRn50KZFzPCe+swzqIWgHXzgkwGJ/Wkqg:CvOVN/VOXSBOKMHEj45Rn6yFzPvMzz3L
False
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.43 KB MD5: 5ef01ad236952c393cb475ee68b94d1e
SHA1: 4d66e1b9cde8a06a1a957d6763c2db4909b47a3e
SHA256: af140a8b7a319f87bd32b85f3d8c193c76272f0ad9a93a710e0b7b363a0303f1
SSDeep: 1536:bjEU5zouvdWzjZ0E+nZJPN1k+R8NLgYoL5sq2n+n7YU3Kb5UF8oLSgFJBg/:nEUpqfncXPDk+R8BoLGqdCVsnLRJe/
False
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 95fefc796dcd8c936fa59c3056f5e55d
SHA1: 5be65811214d7aaf615c8013cddd5d6a0a2318d6
SHA256: 7c30b49e320b0710a7e6a4c3e1d8904e3935e63bad719f881147cd90f6b5957c
SSDeep: 384:8l8Y292V2iJHkMwB43IuQEXtdgQGeu2jifnTLFhfex1IRIqyR:8+YY2ZWLB43/8BnFEx1vqy
False
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 14.09 KB MD5: dead14bc2c4e31d9dc27aeabeade310d
SHA1: 94c693beb8aa1b7fa49d84172b32e521ca849e2e
SHA256: a290dc0887399e52b443033854819908430794c5cbbd7f03ecac66a0b0efa85f
SSDeep: 384:4m4YNX3DKBpA+daIeCTQlNdAOlK3B2WfRBNw/JyJ2Yh5on0+9:J7M/+yTfRBS/rYbE0G
False
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: 5dcea09f85cd4591800d42fc8c055ea4
SHA1: cfcc358c9e68b77f45d93ecaf04613fdf80f6cda
SHA256: 989d08db25cd13c8ed31ee882a740d87fd4e1e674717944ad0311cd22dc94459
SSDeep: 384:XmuXtOYxP+vuBf6bZuEgPdmTHDjP6DJc5zuQmMcNQqgRsMMhByOwPAd7bubN3lM8:XbtZlBSvjmDJOKTMcaq/MuJwPAdPupVD
False
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.79 KB MD5: f45891c15524035b273c9d5868387d71
SHA1: 20ddb496fb457e799bb10502ae72d5bf54beea2d
SHA256: c10721e28322986cabc2b25e60184211a25422abdb2ca8bb78fa3a6b940fde9a
SSDeep: 96:GYFdGQKMnIW2VjsReY7KgyIzSf+AyRpKbTZ3eN0Q:h+Q1IWjReYW7IzSfFUKJo0Q
False
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 66.88 KB MD5: 69226ec46ccdf20e527567b22056eadd
SHA1: fb44c58acba637bf2d0c4613440d89ebf008bbe7
SHA256: 0595d0e912a86298314996ff8549d6d39e660c85979f20a1b1df83a3e65af1d0
SSDeep: 1536:dg/SmNGk7TKJpgjJpKRvlKw36cYh/L+7OGjmuFaAk4dW:EGmCgjJpoh3nYBLRGSMfdW
False
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 10.11 KB MD5: 94af235c30b9a72175468268c81de75f
SHA1: 426b70e8c691077d77d5e955041e773a8203c26d
SHA256: d18f772867ef250d668f87fb14c4ba7b0356d2f6dc0d4828773d10e8d124a591
SSDeep: 192:IfffIEQKikr4fDszQFaZ58dH5mLXj3W80DTRmHJoPkO3n3BYSnaJ6RJpEgpE0Q:OikcDszco5+5mL77MTRmHOZ3uSn7hBrQ
False
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 63.96 KB MD5: 254e644fd60cafcf4eb050ae3d791656
SHA1: 60e0fc442fcf935c56e227af0042b5ff55eaca25
SHA256: 384548ba9d54e10cdeef23388c730673ca588e8c675a1b94790805bb58d56b40
SSDeep: 1536:lIffDTq63MLZU8ZVZAOF/Hd8E8f+/tiLwJn9/S5XxV:lIvN8LKAAmGE8W/YLUiXxV
False
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.57 KB MD5: 84d94060ceb3c885682e7acdb152252e
SHA1: 088c5312aff762fddc6f8962e898b027ef3f96f8
SHA256: d7eeb2624b90ab0059aa9b65c969cff791db9c656e90df72effda7767c84e56a
SSDeep: 96:KP5qtPP6SQZ2wfI+GxfXUTooZFiarXJSc0Q:KhqJdQjfIxfUU0ii70Q
False
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.69 KB MD5: f9405ee087f0688daea3c71d21ccb5ed
SHA1: 69b67aeff8a383bf5865962a5cec59bc29c01c8c
SHA256: 21ca7a0c546e2beb27e93dd18c7180dcfd7eeb6411f8293dc89f765b3549b33b
SSDeep: 96:TCihyEsOIFT8vGUqD3tPauVw/602TICmvPYknIU92Cu0Q:OifGT8dqtnE6fxmvxn9s0Q
False
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 19.09 KB MD5: 7b99bba8e8370d0a315ce150410c63ac
SHA1: 55fbb10155700a85ca7cafd21146e7a8efe46be4
SHA256: 40bdd967373063da43f6afed7c20e38e679de199b22bf9895b8bb537f34a6651
SSDeep: 384:kTSWB1hYkJta38ekqVQ9Sth2Uh5MQTAp3rJATuw7V6lWH8gmnSma3:knBYKtR7ihNYQMtYuw7AIcgmxo
False
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 12.61 KB MD5: 6a7d7c245f803fa79d58a5fc1f97ad3f
SHA1: 93586760b35c6d6043c11aca2220a910b0428e24
SHA256: fa5ec943b758ef824da7589b4e6586099997e1f77743ed5fe056d09790dff20b
SSDeep: 384:CNxMF6wRnJqsP4uBJ/cKUNYPmZ9gGJRwTqehQ:gMBCyJ/FUNKSZzovy
False
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.59 KB MD5: bdc4f6a7642d71e9685ebc45cd311f15
SHA1: 999c5df49e7ac3f26926c326abce439257fa0b3a
SHA256: 97a98e8966d429afb0bc345ef0607a39729e78705c16fbd4f8361dcd15fce271
SSDeep: 384:2x7D10BaAKGg6+vQtOuvoHMnUmqbI4b7r0SLnjVl0BI5z/ejeI4s5nY:2Jhuc64QtOugCUmqbI80SLjVl4Qj2e
False
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat 86.71 KB MD5: 485a6654528b8da2c2344cdbe5eeaade
SHA1: f25fd807ca529afb917201bfb997876c50b7cae6
SHA256: dc05ba2636c979ea067984666206ffc892f473e190afbdc5bfe51c3e11848ba8
SSDeep: 1536:nApM8azMmoxsUA3OIvJIbsNEPZRUQhTMCVR0YrsxWx8vkvHCU8bW4D5tztnymMea:nv6nLA3OIR4DUQdMCPIWwkvkRVjymLs
False
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.21 KB MD5: 2a40075d067e0b329952ff459038d0eb
SHA1: a18f52fd80065c5f06c29df93f4004315675d487
SHA256: 532e4705a14da2a9b09379436db3a29f585142f99c69033c462106903031761e
SSDeep: 48:M/eEdRm6hSI5hSTID2c4EvUoPEbBOaM5p6ETg4J69N5VYW2bRNg0t7by3Q:REKI5hSTa7R7PY32p6Ubs759K1b0Q
False
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 77.69 KB MD5: a7abec74e01e510b6449e8b2ca39b716
SHA1: 211ccc07e92e115aee065a1727799637386083d8
SHA256: 3c3baa8607ff801dff709434f7f0910a3edc299c4e6a86d717d733a6e3f7230a
SSDeep: 1536:6uU5RTYBqZ2Ez7U34pO1B4Ppumkej2yrAycF3d5saOkRn:67TYM26JdDV2rAaOkp
False
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 80.69 KB MD5: 8472fb87594a875a9f90ffd9909c5566
SHA1: 8e50b0de8953b4ee37a0fb9c5a80d53bd35b5f1b
SHA256: 1f599644df9eee65d4337a34fb86b61ab5000afae597e53f785aa1610e97b5e0
SSDeep: 1536:qqXqLTPeqio1/IMpimnHYdAdpsvTDhcnBJg8njyj+yfHCa:qqaLT281/IMMmnqhcXgIyjpHv
False
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.18 KB MD5: f70b78b271bce9bf7dd998edad0651ca
SHA1: 6a08fa5e284725fd11191186b872e36f49e03fcf
SHA256: d190a6af5b5b07abeaa746e9610cf0eaa542a63d3eb4626bc100a6915a9b2383
SSDeep: 96:uyU2n0h1FBq7v7reSJyJvrvH4ynKwpYu0BuKUcoV8MGwuI6L8iwZquS0Q:uH20hf2DreO4TvPKwpn0BupcQlARpz0Q
False
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 18.09 KB MD5: 653551f4f249ceb86b6441fce3665069
SHA1: 15069c679a0b93a0c1c01663abb06311fb872fd1
SHA256: c083cbd28e813b063cc1b3647727faff2144b76440f2514055a8ab83510f0fd8
SSDeep: 384:4epoF7I86xuL+AL312yWSgpfrm+DfPZRQx9v8kXAvy:4e67IzuLT2yWS3+Df8x9vVXAK
False
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: e7434507f1f19704bddac570fec2a75b
SHA1: 10294a008a1f24f2bd7e2da0dcbc0f8a5e68c42f
SHA256: ca33e2eab7770641ce3a2e16fff1f87aec9a683e9ec2ea9be4dc7f4a5f3b29fc
SSDeep: 24:OOZMLmx+w/OQjgDFEXw03lX5eAcELaiWVKH92RByx/lT4WPBAA3RxeNFXrjEDq:OOZ+w/O2gEXNV5WSai+Kd2RcsA3Rc1r5
False
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 0b85ef32c09b96ab7c1a68cdaadc3dac
SHA1: cd9157231df75f4f2be07da40e36ab84287f896b
SHA256: f6591fe63a89750e57ac124a6333afdbc842a976460fd39351f3010fbbcf3e7e
SSDeep: 24:BPQwzIDm+lenUqQJ1jSg5yxj0+GvPByPwC5edU6GznQ77epJvNFXrjEDq:BPFIDNlBz/5yTGvpyoC8U6wQv0j1rIG
False
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: bf976e7f9eaf1ebe1a290233f357ff50
SHA1: 5c63e442c9a2aeef0aaf46773796ff5587adb644
SHA256: c882fd4e45ec11bcdac80a90812b5eef56853cd6c39df7af959d1cc53d0165ab
SSDeep: 24:Re6y3C7nSaRLgf7iRBiRaLT8MLdloHzWxC8cGNFXrjEDq:R37SaRkTimRaLT8RCxC8L1rIG
False
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.35 KB MD5: dec61601a944c3b6274820aec7314f0a
SHA1: 777f0d56fdb4bec7a915bb76ad7966187e4bb9a4
SHA256: e3d34783bab94ee8ff491d2e08896fa3050e6a9b15b2afe86534b6acff8fff7f
SSDeep: 24:K/Z8b3QrHCeaRpNSGA7znvcgo75ZE2jN7SjBrtpEpfMcZczk6ftM10O9PlPU7WI3:w43QrHQN7invcg+bEAOHqpfBcnfC179G
False
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.10 KB MD5: 104686fa0a10257277722a3b889c5e0f
SHA1: c9ffe6d77d70e80920a6e34169d7938eaafa5180
SHA256: bb6c34a7dd9ca905a09b3d8de0c19082421c6e1bfdb3a2a4197125ea2a83a581
SSDeep: 1536:vfcgGYyVdsqyF8gJUxLcjJZjd5JqY/L+MRK9bUGPrGGn4ToQsrEQp:vkgGLQp8g+xUZzJqYjBGPrGOD
False
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 53.41 KB MD5: 7d5cf5eab0f5e0d6fe4c49982cc3f4f8
SHA1: 5cda4a373bdf97c5fefcc4faa7c271127b45b906
SHA256: 9a9a42df5123881e8ec0ec9f1fc2c07aebdd04d8833555cbe731e0ee39d819be
SSDeep: 1536:OttMpv5MuIrhqnLOhXevf8J/hNogOqJK2Q:CMpv5MZ6ShXaf8J/8tqJbQ
False
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: ef571b3db28c86a00af0b468b0f78ca0
SHA1: 8081447a67a322e7aaa3a782a9a3e4e63a9a250b
SHA256: eca07c19a11f5d2d940943943844448b88a10e06628d43318b069028b299920e
SSDeep: 24:Rxc71CTrsvAKbo8yZ9TrPrQQ/AsNgbLx3RLQqF6cNFXrjEDq:fVsvAd8yZNzQQ/AsWbvQqF601rIG
False
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 727c9623178c1c57a41e7bbfee6686d3
SHA1: e452a81fed05224f2c409ab9b2a59edc738289e9
SHA256: db932c503d2b76deb585eeb81de8d8bd3cfc8d68b32dc3ffb15e101536a38d92
SSDeep: 24:vWn7lkibMTCkkEmU06Kv1SLPjUmtwxHNOI8yqkR1P9ayyNFXrjEDq:vKkiIzkCK9wPjUmt+NnP9a11rIG
False
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.00 KB MD5: 4a2dd7e316ac3fee3d5136fa6155c682
SHA1: 04fad01edf6f752e4e6d28136dae9d7374827b14
SHA256: e8b37e6dd69dddaa19ea301daadd180e932759869e460b278c7b5539143e5986
SSDeep: 96:sSiTUV/5tqFer+tGdJkYwSjqY2ROV2a/OBQnZ/dHxlAInStLF0Q:sSECjRFqYlNOmZFex0Q
False
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 79.82 KB MD5: 266c4082ef3be217aca38470f27dfbc3
SHA1: 66d5e7205405beb2b0fcb64a39ab506fd0412ede
SHA256: a093a335bf755263aecc541aba9e346c448955c0c4c3f6454356f59d8cfbdfc2
SSDeep: 1536:rhXZh1FkO+dKna+fd75jPX1ykJZAXgbxBva9UNr2OFEuIS8:rHtzta+fd7dAkJmQbxhjZ2gKv
False
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: 77fa56cfc8fed4d064894f4a33b81bba
SHA1: 99e92588c6faba5146131a9f4cb6ea8619ae8807
SHA256: da72bf79598e5f16ab2756e4cc353c01475093c1d95bd3fc5410ff8852f2ed9c
SSDeep: 24:ncQgBrI+ZYV4St5TvYfSMMICox1RgLNFXrjEDq:WBUUEVt5DeSNBZ1rIG
False
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 76.12 KB MD5: 5e514098f2999cd51531d75e3e0e7f6d
SHA1: 9c6306a1f5c532e3b8105213f3155a0016d1dccb
SHA256: 371d26ed70573e784bc637a42e72eeae874a7f09775ac0d44694c2a26a32690a
SSDeep: 1536:jwfWN+HqTemO9mqMd46iLWzAHkZQFBYTHPJYqSxbbFxksc:jwg+HqFO9G4TYZwYThY7x/c
False
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.83 KB MD5: 3f8605b1f76fba0726e7bb1689bd77fa
SHA1: 075e691a39d0edd4222638106050a216fd8586fd
SHA256: 7ec16f11b85a380b1aaae87d0b91c5bbe5fd32a6acb02dbaf6134f04aff5221f
SSDeep: 96:GNespSees3nykUXhSe17qd/Dd52VxAndFXY1A0Q:GNespSm3g9GD2odF0Q
False
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat 17.59 KB MD5: 618a864bd936a71fae2751a00e8bb7d4
SHA1: 4032ca44afa5c8fd519e802230ae22aeffa7c637
SHA256: 3ec199b144b60c02a59fc4a3ec83204d8ff6116e13a46eaedf87706ad45231f5
SSDeep: 384:LVQBTf68MeKgztC4xYvUFWhfCyLfjcTxToDks5LbAv0uYKjZ5A4ubMJ:LVCTf68K4cZcF6fzjGTU5KRYAZ5A4ubg
False
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: abfb813e106feb03dcdaffdd76722a73
SHA1: f089b3e2035075335bf6bebb81a7951cfb392aa1
SHA256: af0a109d17973aa6c4392b6908c3cbcd2f53341873d06e80727980ec543268e1
SSDeep: 24:G8RkCUui/kRmdKsniupDpWCsI1aR/vXcNFXrjEDq:GXZkRmdXniYDN6X01rIG
False
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 5.93 KB MD5: 5ceda9210ce00d7be85668f0300ca89d
SHA1: 8809e0806c3683661e5efd981d3ac5bdce0fe0d8
SHA256: 38738d5f3293b6243cf76bbddb18e0815dc1665ac4c9fd199ca277a3bc907451
SSDeep: 96:MyySn1pd+wxxXb9yqtUN7yhBNGVSciWGC84guI780Q:MGn1psAfVUEhBcPiWdGuV0Q
False
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 75.27 KB MD5: 8dbde3f8955498c595a7eb038481d0b5
SHA1: fe649f4063c6aa7c1648d2bc9e7eeea636a41132
SHA256: 76b03f7bd25671dddb9496fe7969c2b8b4cc2ff7c2d2a36412078540ba88d66a
SSDeep: 1536:gFP80ANtU0QFpE83QJ7ATzmjrnMYSPdsETM1ZRaC0anbmHF99rFe:CiNtU0QFuSuM7dI13vmHFFe
False
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.00 KB MD5: 4064e735a44b16d659230f41e7d9f3fc
SHA1: b561e98b6c73b0b45e2cb5dbd33d8f337b584b3b
SHA256: 201bb8d4b92f8c89fd593a48459c7965afcea588668e848328c596359c521ebd
SSDeep: 96:6EZUd3l/PLFDp35a1Jq6YR/hZBGk8K4cIURwT0Q:6E01/PLFFc11YZhZ2Ss0Q
False
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.10 KB MD5: a7f4a378bc5f3c66395b29f48260582f
SHA1: 5c4b523ecd3ce313c9f1ce5ccef2ae24136d73af
SHA256: 1e9197a72a79760b9bdfc2c259587d272741afe6b403607dcb143fd7ea55d98d
SSDeep: 24:8U6h/V1/jdfFXvC9jkCyMnDPsGjwomMENFXrjEDq:8th/V1/j5RqlJDOoDM1rIG
False
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.35 KB MD5: 83249a645924193e15a3634190cee7f8
SHA1: e68907c7708518443524c03ba0a507e3cab96b6d
SHA256: b97d61fea41a1a3367f7e7fc3169868cc5dc5185e51e906bb3f4784dc9163118
SSDeep: 24:ZfIasipuqr4s3IWHn5/ZIzK0vE4cPipSv+dOvTtjTQVUIqi60McrhNFXrjED8:1IjWqs3hPSKAEt+dOWJqC31rII
False
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.51 KB MD5: bb2202b7316e3ab60f236083ae3e9131
SHA1: 261465ec36b317097e85a890022a4c3ad9940b77
SHA256: ad87c1d47126709a7aff0bd0a16019c237221ddcb6ef6baa62379242e73238fd
SSDeep: 1536:fbxp/toWoJRnFo8+RJGn0kuRE9X3LgWMlSwpYsMQ:fbtoWofFj/9X3LVa/YsMQ
False
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.62 KB MD5: bfbe041adb04b7871985bef57b7fdca8
SHA1: d306ac735964e5d68b4d001718b89df0ef659969
SHA256: 0b3a5855e0f137b08f010b2aa3a55502d7873e24d54c2404367bd521e6d5ec20
SSDeep: 1536:noDFUBIZgD3+jHyIvzXfFLV+bmkSJZivdJn9M5YQWfjwArm/Bsw:nyUBIKT+XDfFLQZmZivPn9BRfjwMm//
False
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 6.39 KB MD5: ff9463f7ba223a103c23a69b60071cca
SHA1: 887449d56d5f1680125ed25df7804644aac8d67d
SHA256: e13c3bb75522f7a1f665c95e50c3a9f0dc81b09f2707f9784c53848805e59a64
SSDeep: 96:/AvteO0vHUHrCL+jgrSYIGhyBonqK3ZD/zlwMXyKTWsUzN5H8v9/QCFlKortgMjS:/A1eqLClXyBml3XozN5CyqVry0Q
False
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 4.14 KB MD5: 8a56644ca4cc85bccac7184267ceae5a
SHA1: fe70356543387dcfdc8f7bf2d67d2c75fa2bc458
SHA256: 0767de23113cc2fafc69d2c867fb706949b4cd92eeef35d4b1aca9ec2e1994ba
SSDeep: 96:2Ggo+e5pNegF7RRw8ezaTwCSr8Nd1aYZV3xo0Q:2NgFRw8zTwLr8NdgY+0Q
False
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.02 KB MD5: b31255052ac159b2c87fb25e49ffda77
SHA1: 431fa98728e9bbef5fcfc82923a503f5125c5a74
SHA256: 3fffc827250232e471a6c974fb91d698ef61389f387d48ef48ad07d6fc79a134
SSDeep: 1536:zMq3WHj14XpvzMVNErK1w9EUzGCnYAmswV39DpVFFkZ0m+6p/HekVBn:B3WHj+BYErTGOYV3DOk6ZHekVV
False
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 59.65 KB MD5: b9a9f9978ff68357e8a4d1b1e2e6b575
SHA1: 84e93fdc7ad90a7f228147bc02b472d2767f6c7f
SHA256: d844e0eac32d65678c9b24e90ca247bc5da65d52f3baa9a2774ceab142372ea1
SSDeep: 1536:S/s/dTwS6RMK4XZeQhVDjH0WcAOgqeuhO9cI5N3EhlmI:Cs/ejCK4EWDb0oOgqXhO9cs3k
False
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat 3.22 KB MD5: 1af075c2c5ef49cad84366244e0c1e46
SHA1: 7605857247a1deb83a4d2c90a8fc906c8b107c2e
SHA256: b456c4017e4b6ec576672684745e0e2f220b34a3da81af5c8a1ce4f1bb9bab36
SSDeep: 96:V852yMHYTnSDKfDpImL34kRtyVdXXMWb4zJs0Q:Vw2yVnSD8DpMAy/npbR0Q
False
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat 78.37 KB MD5: 8b20d921dae895215c3f68ab65bef7b5
SHA1: d234ac0121b69b3bcc4926651582bcd059ccf206
SHA256: a58c42d8e1389724e9a60569c8d18bd4a1413ce4c3d58c5190e9264566e51b5d
SSDeep: 1536:sWCAEekvM3MzFzWxqrzEeznrfebO/Opk6u3O9lBv1s0v6cMqpBgEmINpT:sWAHvM8zFzWxBQfzyk/O9f9s0yVmBXZN
False
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 197.32 KB MD5: ab59085240935ed52048bf7d90ee6bb6
SHA1: f47dda9725d1958f65d50a6063f3779354eafd91
SHA256: 0031e2973ab32a1989543ed0a9f60bb3d390ddcdced693bae858c14c46b65213
SSDeep: 3072:i79oelXMyy8hK0caz16oetPpne+nV3qO0xXCG5rzFXtBAi+G5rCE:i7GaXJphK0cc6oell133qXBz1tBx+amE
False
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat 10.13 KB MD5: 43e264d21cbbc2b9b33612b683c11862
SHA1: 3199a541431d6e0c61dbac487c53a690de823bdf
SHA256: 3ebf3d7513366f9b799dede1c43d70a600948f85f488b31acc656aa6b34f08b9
SSDeep: 192:40xoD+uxXtxaysLsYY0bCNIe9AA1rNIDlLk7K9fn9HckQAW2LAq:BxoD3XtYrLsYY4iAUqDlLkOhtc+W28q
False
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 91.38 KB MD5: 8c496794864651bb1da5530e1f0acb5c
SHA1: c3773810179aed18d666c5eb4e471a58894c735b
SHA256: 56bb80b40cf22a0b4ee77fbf22666c6889e92d1a4df25845a269092612a371b6
SSDeep: 1536:BwScSV45aFv/UUcSZL/lCHHQm/9x4V61DGROnBe6tOHxPb3P5d///tYZmYytw7sq:jcQ3vHDd/OHj7+uGRUexLP59dG6w7sY3
False
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.37 KB MD5: 8f38f3501407d230699c71a7015f708f
SHA1: 49f85fa01df47b0db7edd6f2fe8a0a37cdb5a66c
SHA256: 198aaad85fd678bf92f40264edb570c20ea8269599c57353fe777de265dd5f7d
SSDeep: 768:bhYtFy6E6crnRqDy+ktd8o1VbJrHUsv/t7PHszkruutA:6tFm6crnL+IlNTlL76
False
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.37 KB MD5: 3efe988a525814b328c0ebb96406eed5
SHA1: 3c5477b3a67ed76e0600712a5fd6b9e96cc7216e
SHA256: c61b46e5932f6b621230cf21a46add930c81d324c677a816e149cc7ae163910d
SSDeep: 768:NbMSpRVFxYS3maxzxEJmh8JeDnttto5IT971WLqrnQmR0FQYuDy:ZLpRVFvjE8h8Jejho5I5xWLqrnQmR0FN
False
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat 15.99 KB MD5: 662d7932e6193444aaf8213efd72fab9
SHA1: 31acc93bbac2c8f3fda060dc69fdf447e0bd99c4
SHA256: 772ab40438d696dba247b5b60c9c0fba66257c9e53d5806bf338f54b94271364
SSDeep: 384:V3lCJd5FRY+EsKXLeWp3B1ocdEvJ27B4HjtTRJBB4A:RlCJdlPgXaWBPwU76RJBBT
False
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat 36.08 KB MD5: 11e5e5e4a66be55a884752073b325aa0
SHA1: 917dd14cc824daf7c1548852fdf3cb9b488c004e
SHA256: 99846728fdb70f7a3fe4313daca1194e01180560db4c51bec24012c4e86cb83f
SSDeep: 768:3DJVr6IjLlQVBmxOfPvvJx3uNq7pXrhXJD7li:1c+Q3mwHz3uKpbX7M
False
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: c2256941d7933e9b9403b814b2b57908
SHA1: d9fde4bd34616682651cba2fec08614791cc023c
SHA256: c1fcacac458b1fda083f5b54d564835915f7b5dc6341f6fe3918848fb7ee7f30
SSDeep: 24:ETXALkjtY3qfdxYZFT/WHs9yrD5U/gfRA9blGg9mwqVkdrNdy/I0NFXrjED+:QhtrbYnWHAyf5XO9wVkTwI81rIy
False
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat 29.65 KB MD5: 99a9e9b767d6537c33207b07d863acc6
SHA1: 76c0a621ec6defe2bc6e04e40e56e59aa92f0fe4
SHA256: 2927ce8a95be96c6ad37b061af2557a8d04a98f852b325666e2b1462c0a8de24
SSDeep: 768:054U91yrULQnZYn9pRDKZtHsYBsOCScQ0Mv5/EhT3UpLWu5m:05l91GZQ9rD4tHs3/Q0M1AIpXk
False
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat 10.13 KB MD5: 2b26c7612f3d0866f725b64f579e0b41
SHA1: bd724f8bc2baa62ce62bca8166820be5a0328322
SHA256: ca01458c21f27c2bd8f4b35ce8ff4bd2a26dd97363bbfcc79d6a8cd8faad5e84
SSDeep: 192:luRK+gRIEe7YjfpXWjtXBAcPf/o7D9dyLjjLpYD/HJvZBbb/X:0KRjaCxkACHoXjyxOxfbbv
False
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 265.91 KB MD5: e26e7f84c459dbf0cc5d379ede0253ab
SHA1: ea62e8cc34b9cd92af47b67749bbd9cfd9e50825
SHA256: 828ddcebaa9cb313c1668f4a41b37817846027d897ea25c8f5f7c30bdfa9f97b
SSDeep: 6144:Z6emcK5EB4NHWBhuYeDVm4t/44FIiW0fWOSOAcCS:435E6cPeDI6ze2WOSOAq
False
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 40.36 KB MD5: 2d4e66b27a7dfbc5de1fa832d5783e32
SHA1: 0447c2bdd4175a9c9a3fc90d03b6687be04fa09c
SHA256: fe60b60d4afe5b24c5b0e61c8015ecbce76ed6825e3a48005a2822fd0b28909c
SSDeep: 768:Lfx2NqbRqSr40Y76qStWY7Cmzxw0TRK99jZJBiFZNvQq0lnZdp2ImqAN:Lfx2wbYCf0Y7TVroPzoFZlQFNZdp2F
False
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: d17f0fddbfbffa380d40fa4aab13aff3
SHA1: 55d39b8bcedb3908b33f35a5a9cd536553937825
SHA256: 834078199ae0f05c433567ef11720efec24cac9352f5da2b76345b089f074fc3
SSDeep: 24:i9KdF5vOQNEUAP462AzuCMvOplBUB0gwgvmPhL0rIxOn6Qiw2+z9i4/T6X36jwuv:i9KHtzKlPLPBMKUyFOmg4nQiezk4r6Xm
False
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat 13.99 KB MD5: d539929b494500b13b0dc4e480882cb9
SHA1: 7ef2df0f7bca737b16732090d6d43a2d6e57dcc2
SHA256: 8258836431d8163fb4f16c9aded2cd67b5396b92048ae09a44d76a2d860a1f0e
SSDeep: 384:RZ2XSgikCInqoKJqKlBwCau7+tIqcTCn3guwB3IAdwpYwW+:RZ2fNCudKJP/3au7+tIlTCwLB3l2Yy
False
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat 38.23 KB MD5: 45e9d1e70116161bcd4eba6c6658c7a0
SHA1: 6e06404aff344014438a0741df60d438f6093f5f
SHA256: 22e42bd17d4a4656c614a2e2d22e901dfba0d417bbc5a3f2adc6ab22b360dd5e
SSDeep: 768:OPfyQKLiiNAwR/DEeAINUSnPth5SJdfxElJxYUMC72dvAe/fmdqSj:OPfyQ6AwDEeAINdPjkdfxcLqvLpSj
False
C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat 173.83 MB MD5: cc75e7bda8993fedfe1a6badcf08dce7
SHA1: 9f7920f930c3874402c2d3c14535e2bdd1fe4eed
SHA256: e104262286e666244be9b1244b073d074f316420ff783d93d664a93ea8c7c99c
SSDeep: 196608:GV04YyKSBXZ35w+KBK2KJKDcloT46ooP8ZNoz+hK12RP1O7lT:z4Y7qZ3CwFISoT46ooP8Zyz+hm6Mp
False
C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 3.77 KB MD5: db7cd03cbc189c48358693db52a3ab78
SHA1: 02d08c25689086931cd8259142d49be97679e3ec
SHA256: a62780fb776e4df4e099143f6a17ffeb8d0d7f1f14638910f69a56ada59e514f
SSDeep: 96:wmW128T/tKrObqSbUVtkvkY1LMleZSQuQJI08:wmW12853q6fvkYWleZSQhi08
False
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 1.11 MB MD5: 2db797bc9e7c395401d418d594866fb2
SHA1: 955da6f915f171c94299560c96f9fc58c20be7bf
SHA256: 1d45cf40a0242faec55d90c00c0a0ac50606ea68300c06ba1c561ffa66c9dd3c
SSDeep: 24576:G/ULu6dUmVHx/c4gm23v2C6UWs/FTzeyAi56wql+EamD:GcLu6ZR07m4v2C6k/ZC0ryD
False
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat 101.87 KB MD5: baac54b5947ec479258907f872ce090c
SHA1: 5e2cabf025dbdcb14c9fd9f279cabfa139a8122e
SHA256: a93960a0b2826629ab6abd8d14a7ad4e23dfcee24ebea9d9997de5b41f921f60
SSDeep: 3072:rPQ5cdzviiWqHFovSB5D/sfJNTD+kWcDoqSlwy:UurBHyqB5wNTvW8ocy
False
C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat 64.25 KB MD5: 02068f1cd61d523c20a8b0d2050785db
SHA1: 1954652ec1d5a19e3b392f45dae6543633537d5c
SHA256: 7b011ffa1849489bba48f7a3fc86e65d2284d70c2fc31e17cac9b0131c3f613b
SSDeep: 1536:VxLGoCkDhV2twNhubs8ulF0B5qHfkqwnhgajfpUaIZR5t:/3CuLJCbsJlFIEHfHnUUDZd
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.30 KB MD5: c4185c1742acd2f072ec7403b91d9e68
SHA1: 66260a6847aa443b1005d850d717c919fcb7abca
SHA256: 4b5d73d093dec425380ac380863b6e21f9c4b70ff2d425f9ec5936721c994991
SSDeep: 96:hxNKuxHDuE9/vqRJDYvMbRsWGHylMg79dVsvM3rl0E:hXtZCE/vmJrOWGyF73VIO0E
False
C:\BOOTSECT.BAK.id-B4197730.[idecryptyourdata@cock.li].bat 8.25 KB MD5: 86ecc2c13cc1d08f48686ae9afe8792c
SHA1: 9201df9bb636cb08bf14d5436946c3f181afc5cb
SHA256: 7a3e3685f8ae9e6b9d815eac9f0fdeee6711a81b5a1abc236fa50164f07ab9d8
SSDeep: 192:EnuCYy5LjxqEuIj0/HRfstaw1em0Le4y9oOu0o:WuA1svw1/mr8o
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.62 KB MD5: d0e9ed67347391f5160584dc39eb8a02
SHA1: dd2847776d0db5fe705f9fce8698a00f07ae77f2
SHA256: 829e647ca2ab87fd26114c15aa7d705ea8b945b8139e173652dfd070a7003909
SSDeep: 96:Loaw6rqL1z0lmPg/c1qemYM7mJ3BklLgwhokoPPaQkjguR0c:Rw6A1zGKq7YOEKulkGPZkjx0c
False
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat 4.93 KB MD5: 07d8df4642c1cdcd29edf8b291ec0401
SHA1: 43f198fe3baf73b1bc0232c823dc8590760f89b3
SHA256: 927576ea581b216e212906bac4be2d74f489b958300817986f6891ff65232067
SSDeep: 96:77P9GD5GlGSeS2j2qHrerK2WasIdJnDlOdUU9h1qNMF7LcbgZH0w:77kD5GgStqkLJRO6QAYku0w
False
C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 852.27 KB MD5: c07418d3876322945b7204296d88b3b9
SHA1: 1270c75d75e5dfbef2dbe3accda2ea06cd669940
SHA256: 8ed8ae2f302ea2b886b01c0ab2ff82a5bb0c83f64be8e3825386be1cc3f58d6f
SSDeep: 24576:iw66gZBrVPP6MmenmKjfCig2X9BcxN8icU:l+lPiNizLcxOicU
False
C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 2.56 MB MD5: 1b15d476cd5e5da9666f24f2b0f6ee05
SHA1: 768d1d44ca1068f05c662d6ac20f1cb413fe5784
SHA256: 776a50f58e20393c490ec035ef6dbcb343e360bcf9c42e5ed25fe01166075ac6
SSDeep: 24576:nc+BQbPyxbs4rONS5voMfjhOGxy511DtbGJDXSsMBF5fuOSVUzQ704:ncxisfQxoML+5ZbGJ7Ssi5fuOQG4
False
C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 484.27 KB MD5: 9d81dae26ee92495576b31448316c75e
SHA1: 8d358254da4af299656d74bbcfc1a68bec5f932a
SHA256: a90fa5cc126809cdc1fdb6a6f1edeaed41404dc25c4bfe4e74dc6ac60156dea0
SSDeep: 12288:TckBpyc0WurOLv2fNzQe9pdFzIfxWS7ndM7b2I1g4H:T5vyBrOatf9pd+ZWB7G2
False
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat 180.75 KB MD5: 059507f9c72450a89b7d1a4052d3b741
SHA1: 4d07c8c2df1b1281d457d17a0ac430823a017b22
SHA256: f03122195cdb24084b97088a397edd9e1677b4747e9b7db4f6cf866804172607
SSDeep: 3072:09L+QapwxlIDjG7uFbSCIe3tKM5UjdFscX9QxZ0BRXplb/xMg/G1D9TQycTNkLD3:IaUMG7uS1e3tLcX9QxkR7Ba9TQycWhv
False
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat 76.55 KB MD5: 99fece5d5ad338cc980d49c53d2c88bd
SHA1: e901b50a64c961738a75c839d6453df205ffee2b
SHA256: 4cf06d09b2eff9af42abc0847dae73dc40b8dd86b2b7ccbab4a3bc1fce24e44c
SSDeep: 1536:befB9VFgDsfSU55F634Pt+XOnDWBo8WW4mJwtmARwBpUGo0sqRp/ti8d:ov7gQf7F6IQwWeW4X0BSusWpl/
False
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat 788.58 KB MD5: 9644a2e7ad61e3c8e1a7aa07fa614090
SHA1: 11cec3ef26e1d7f80e267e4c220c7f1ef1325cf9
SHA256: 6baf7029cd9a3e8ee46d27d48ee1006a4688f642aa6e473789f4ac610152e365
SSDeep: 24576:ho7WpZnTkuqcLSjQgWGahZrmpz8DZkVyjR7+rPcTp:O7WpYcEgrhD+VKR7oUTp
False
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat 92.75 KB MD5: bb71b4d0797295f4fb7e2405dc638495
SHA1: a97b6b66ca28a1fda9739cd7625b422130a35f01
SHA256: f68519e5b5e19ba81776c923a61df37696171a83bab3107054bf66ecfbcd018c
SSDeep: 1536:ltoeGs4ofm0PTyM1wHgFfvqJ0GXLoU3+tHzYLZFEU5yDvzXX9UVLPT+NP4m7f:ltOsHO0PungFHqXXLrxLZmUarH9UV2Nb
False
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat 288.57 KB MD5: bd57223e4d6b6ce445cb6694e2483cea
SHA1: eeaa2b9f327dec2d48fc30a66218f18848c279fd
SHA256: 2c0fbdc404cf6baba258945d397326640da938c31cf7f6a69d03eb7194c4358a
SSDeep: 6144:l9Hx5ofz0JcEvyYKSDSg0V3Dck70X2YvcJFxnnNFPxxv1oBfz:l9R5oQzzKx3VTnomXFxnzJxvyBfz
False
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 890 bytes MD5: 04b0de182c1e54245d1f66f4ff1a9d1b
SHA1: d7730105ded16c147319fbe6f2372f35b9931733
SHA256: be3b77afaf6754c96af5b9d373c022ad1312f087f1600e69207f7423c66de2ba
SSDeep: 24:T6QhK/LSATgH2uWyMSub1bFtW5fCpXny3+:T/c/LSPH4jSupS5q1y3+
False
C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat 410 bytes MD5: f32077b329cb1a1337913cd55d10514c
SHA1: 1ebbaf2b1a34df7bd2dd47b7341f7d248a8da6d8
SHA256: cbaea4c568eefc4dfbd536d196115eab35be54c0a4f17f44ebb7f8513bd95d95
SSDeep: 6:ofpPHmZrHaKkli25TVgPBguHCpvbuoZLwTEa46WC2EyySpdeXUPSgu1lw6QGyAEk:oZGZrhkwUTVgPBguHE4X8rGUKguXny3+
False
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat 1.62 KB MD5: a725dfab531eda124bf03cb59f431ec2
SHA1: e2d1b16535feafc58b9bd2319b1595aa1fb6160b
SHA256: 195234682e75fbff6a4fd8f50d98e4ef968e26e82b63d130f60620650dc345f9
SSDeep: 24:jaog8DXZCY47GaZC2CYGacx0Y6CIpfDM03F2p7wcuh6VX9ZBkr2/6ey0kd7KXnyM:jpt94wYGacx6fISFe3uh6hlkrkJIey38
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat 15.15 KB MD5: 3b973b24eb5634d57ec8aecb16389e1e
SHA1: cb62932659cf38152a6bb27e9f975cc3f932077f
SHA256: 13b5a9fcd8dc298a867091088bdfac3df36a51a2b142b78990769d14882534ca
SSDeep: 384:h0Za1k0LE0oUpMH49gitknbKcd5nlVKCwDBI1q:h0A1ViUI9it45nlVc
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat 8.62 KB MD5: 50068f8a0c50c9a0644bd48ddeeae6fd
SHA1: 8a9ee73fad3c74795f9f421f625e22c731988314
SHA256: bde3fa65d5116bb58205357f8d197c46ccb4763b878ca924565db02607501961
SSDeep: 192:w6GAM5ebTkSCqdwvNZp8j+U4OSPjsz85O95SFaA++T3QkyWxQY1f08:FGaTkSZGNZFvF4IuSEM7QTWQl8
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 404 bytes MD5: e8eb324fb2c0d24ed000ebc46e0cb05e
SHA1: 990094bb4842aca635aec65e88b9e11b8310a32b
SHA256: 5484332261339adb51ad6cdcd941aafa8f97204ec8a67bd0b8f6ceeaf03757bb
SSDeep: 6:MsjEMMs2qWTQS+08frH5tbciMvnOClQEyyShqFWXUPSgu1lw6QGyAERAl:MTM9qNUj7MfArRUKguXny3Al
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 434 bytes MD5: 869fb6b70ce8064cccdc905c670081d8
SHA1: 409554cd6ad2358cce6c6f621861814b7ae67e85
SHA256: 89d985d77d216169f985629cd10d58831c0901ee246bf47fc1f9e1ae4addaf69
SSDeep: 12:Ypko0g/bXLquaSmdTVCbXa3OArMBcUKguXny3Gn:wkhcb7quaSmdTQ09Xny3G
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 20a5ab965d11f4b400f46220fb86f0ef
SHA1: 7e61c721cb2170b9b2d4df241e68ee3c5d86a02f
SHA256: 9a85091c11f7e5d545fa02f81841aedd15372f06974ee957f8a49e520b87cd9c
SSDeep: 12:C/zlvYANvBImp8ytaEd3H5Ar/BeUKguXny3Gl:CbpnIIg/BWXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat 14.06 KB MD5: 680f94e20a86d4e96141b9d2ef9eaf05
SHA1: 23d52d4c397b4bce99efe0005a7cfc6facd0fd91
SHA256: 1e32025b1a78978aa45692eaebec4e8862c9673863b257c5c11818daf9e99753
SSDeep: 384:8O+HJzc5Jg6gqLSXRFV+VnIIkNiGcEQz+:HIJQ5OF1QINiGz
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 5920776677517944ac72c9928101fe8b
SHA1: 83fbed6ce0ec21567757de7b307bfab33d521208
SHA256: 48129a2256312075a4ca0abf3b36dfaace282fd8bd7f6b9236503f8dbd6a0d2b
SSDeep: 6:rQ2EJCmkhFheU03nL8ap0sOVXp3CDb5nOClQEyySuDoXUPSgu1lw6QGyAERGl:NEJLkZeL8K0N530b5ArvUKguXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat 7.87 KB MD5: ff573fa6b538bd6ed28e696aa95db447
SHA1: 03a04b1d0512d08cbc95e26e4909eed779c40cf3
SHA256: e9758a082a2be1cd663c227f0aeaef1ad08f9d7d1799fb40c31cde03c1a4ad50
SSDeep: 192:Z2NUiICFuD9v3IzoFKvtvI9pzNkpajDpR4+nXO+yNLU0C:4UifF63ICKZMNY6DpR4++pNLbC
False
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat 12.21 KB MD5: ae1f68feecf68609d8f5b1e4b28edecd
SHA1: ffc5986ed6cec585b5dea5bba8bf876ca6436bf5
SHA256: 3048e8889152022e55ebdf1aecc2fe206162db83ac965289e1daa9d54cc6301f
SSDeep: 384:payk0URtfTF09On+qI9BvLgplZ6rHH4+4UWrBQGY:nk3TFLuBjKczH4TNQ5
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 418 bytes MD5: c7f41d6307170bc1f3c4f3bb9ea62d63
SHA1: 809703cc4405e3fccc99233e6af1c16d9e6539e6
SHA256: dbbac8d8bf80049311f6e9712f843a7be4c67a5d4b17d58b94c3d9669bc382c3
SSDeep: 12:zCHxRVGd+CaZ5UUgrh0/S3qArpUKguXny3Gn:uTVGd+CaZ5UUgd04/Xny3G
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 422 bytes MD5: 720eb913e755a9ef4f6a7bea70ae5c0b
SHA1: 6746043d362fa3b1e53eb145dd3290bec453cdc6
SHA256: 0953857a8f2184e350df3cec7db2ae5a5e2c53c22c32733f691365c0d44d3805
SSDeep: 12:ZES59uXlH9lS43vT5Ar9PailCJUKguXny3Gl:ZAfBghawKXny3Gl
False
C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat 280 bytes MD5: c20cc1c1950bfbffbb06405e490989c6
SHA1: c371c32b56e1233685a4837d143eea34d7ae1e4a
SHA256: 42e6a06c34c5a14c54dc370d22f4e84a3ea5294df71f6f3597f953183fe2ff51
SSDeep: 6:/CRhVpprfEyySmS0NWXUPSgu1lw6QGyAER8:6RhV3rr0sUKguXny38
False
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat 103.25 KB MD5: c08aac48bffb590c351bcc342f2f452c
SHA1: 357d17b2a6a088642f335c5483dce47350f67be3
SHA256: 6a000ef3f44088fcc71237c48db676e3167f3e6e70c54fea4f4056d6268be343
SSDeep: 3072:x4JVHp8Znnm2L5w8b1js2DRqasaIKPF6UAP:4+mIxA2DsnsF6D
False
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat 62.71 KB MD5: eccecdd18e9f5ca296e14a700552c404
SHA1: 891166d6eafd6f4c5e083f71be5df46acc4607d7
SHA256: 8772356ba2afa437f826e6a44437149cfd832e54541beb79484a250aded4dc4a
SSDeep: 1536:MD7tLgRWbiwaSFj6oz2ZUHpwVAH6d+VSvEC9BKOPvsvnPYurF:MVLg4bJZ/zVHpwO0+2jTPuAurF
False
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat 4.37 KB MD5: 954df46f9939bee962bf64ba933ed1ea
SHA1: 4884cc7ba1ec2002ed2bc6bbf79a7de6f48cebad
SHA256: bcb1947541ae5906394cbcf28edcd593d1f1665a298bcb7121d22ead3b88ed42
SSDeep: 96:6sbimiCbE3YdEPzve6YPGd2bLCbgheNMQH0KZl8sNhGFd0q:6smma3zPTePPe2bLsgwmQHxlxNC0q
False
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat 1.17 KB MD5: 4ef37de16d57f9e2599542d4dc11e093
SHA1: 366664c569d9ba66ab0dfaa3a26ec67437029fde
SHA256: 4807bed8326609e5ab8a949e487273779459db0807ac4b1519824f0526361adb
SSDeep: 24:4wsHeYzFmOMnFJdj7MaNVLA2jiUKX4baOtJ1/j5ZCtU6qZLWPwJFoNpXny3o:4wweYzFmJFXjwfTX4RJ1L5H6qZtXyy3o
False
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat 141.27 KB MD5: 4a747be0c8144c65e64d533a8009317b
SHA1: 8a45ebc6d50ff1f6281dedf8f72c0ebec99e6739
SHA256: 144abf1a3dcafbb12b971036d6ac5f4931a9e46ca637139d612c335d81496e6b
SSDeep: 3072:0Z9BBFL6q21K8XC4IaApC+9IPpz0H80ea0bvFN4xgvBNn2tP+/0s:0Z9Bo82C4GC+4hT0ex7FN4avDnMP+Z
False
C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat 94.08 KB MD5: f2aecb4372e41735f0b95863f9d69e63
SHA1: 258c0820f3607120b39956d6b0b13b7ec45a75eb
SHA256: 7052cd71cd0c9d0a5443e450fafb98c72215749c52802108c1be46557611d0d6
SSDeep: 1536:6kU/vBr7lJ1W0hkwMM3JjZbI6y5yAQ4Qjr97ogoe43ljBoyfqkphVz+467+gGcHQ:UXlBW0OI5Q5Q4mqMyfHnVzDK+mw
False
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat 434 bytes MD5: 0ae9a5a33ed6663f54c73bccb0a7a6a9
SHA1: 6bdd40785a601a13bc206a5ed174d70add187881
SHA256: aba5c4a26aff97479937940985c13d468fec51b7e4cf339e9f7ed6cc8426d6ce
SSDeep: 6:gvIp4e3mv9F+7fz4R6LI1L4dDJ99lip3CDXynOClQEyySRb6HvsfXUPSgu1lw6Qw:n4ey3+ACIil030aArhmHvcUKguXny3Gn
False
C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat 6.42 MB MD5: 644514b1f1b6c431e6b10ed2d3f8a3d4
SHA1: 5928c691a1060a10488698c28bba85be5a785b9a
SHA256: d767851c519437efe4ece80128a185f49177e6e8a8b38ecee4887f083f1d0e1c
SSDeep: 24576:54vzz1Y5Zj9Y6AOwaWVNWWHHzRu1k/L9chbUF/Tx7mWqn3gVtiBwGFwRusBwlNSa:5qk3NIX3NIIaMeAtJXXuHhmAms9HV
False
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat 142.04 KB MD5: b5d2fedce20bc1a2b371bed5f4060418
SHA1: 6dcb2fcde74fc6f0711e9faf26b2cfe0d305ab7a
SHA256: 808508f84a3bb3a507ae8eb248d72f88dd4e0921dfb12984bd6ac0893b8e7011
SSDeep: 3072:A2JfWyGmhj9lFr858pEjJXRnVwu/yARus5AiwO:AGWRU9lp82pEjPVwW55fD
False
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat 544 bytes MD5: d6c7a9579302ede41c11166ccb6c851e
SHA1: de8df4f8b40e2164319ac51b053236562ac31be9
SHA256: 1552ed7f8da21855df92bdaf59524be1a0a97de7ad12ed88c10e5dad94f55b47
SSDeep: 12:3PILj/IzjpAOG7QrxyyPSPJdjc1jIRDrn4ilcUKguXny3sl:fOj+AJQlyyaPJKkFn4ilEXny3E
False
C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat 35.73 KB MD5: bc777333d16541408f29c4e5a47c8778
SHA1: 0803cb468c6ccec800d81a9a8ecce05894fbc6b8
SHA256: 225e1a3b733c6bcb77a3f808ea959066a4822a53a932ef97bfca22494dcb77c1
SSDeep: 768:ukmkmR4qkvOyMNd0g3czGtTITWIWj5evYuN8u7qEg:uk0KqkmN33HtTITlWj5ewuN8uO7
False
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat 92.49 KB MD5: ffeb9808ae5b600479d87d753683fe6d
SHA1: d61114f0f0d21c2d4e4577d6868b81767c38b684
SHA256: e3128b092e24c21017d9e4c2e10421c8d141f6243cf573917d01d38d0c70ab13
SSDeep: 1536:zbXBN6EBsXLY/u2GdSn2n61NqByKJXxSh4jqqpxMqmAiUe9ehH+t9jGmvhpyRjxS:HfKXLY/uBRuIu892Oe9ehH+bychCbgD
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.81 KB MD5: c521af745b4627e718898b3c7bbc443d
SHA1: bb6b0a12330591523534639a89e1cfe332c9d821
SHA256: 15dc22441e3b683d2aebdb27da04724e19388bba6776a76e8309b6c1e7d36e0c
SSDeep: 48:OjmGY03Yr2OBqvEko2Zjr99AoKMH51L7Y6uFTXOZZy3a:qmOIrnqv/om92EZZYlDOZZ0a
False
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat 2.84 MB MD5: fef392ea657a35f5e392826a3a79b912
SHA1: 72e0ee6a46f9c977eb79a510c6e38f367718325f
SHA256: e43772dc7d9ee6b588706a5f24995519f7e0df1701df9957102a24adc7ec3b4a
SSDeep: 49152:WV4YaGoDumT1r7AdXZy9KU2KUYxs35DKZ3OIKUuwaGeeXvG4:WV4Yab1PAdXZzKUYxs3pKZnKUmGZl
False
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat 170.68 KB MD5: 8a5d4fc648a90b05a9e9008bf2ce8fc4
SHA1: 928bec8b7a00026cbbe003c6fdcea0e7103446b0
SHA256: dbb50a9f6e3f6bf3c57cf497813dc6ec42838da91ee474f9337a7baef4911a8f
SSDeep: 3072:ERcooQm+T6ytZcNsgXWG7U2AccdzJrjUQL4Jw57ogOPbJQZNX3aD+2zk:ec7UT9tiNgGojccdzhFUJw5E1PEN4k
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 378.59 KB MD5: 622253340f0a3820a4767d5069a9cc4d
SHA1: d26a6853c85f491b03240e7272f081b844122175
SHA256: 93d535a59ec431f38be34b325218671067658c8fb5ed0c4089b3e8a15898f7db
SSDeep: 6144:IXGcIfxjrqgmV8zuzW3hRl1jPF8dfTrGwKPyEXxHjFkFLHw+kmH5zalRBV8VC2Rn:I2rfRGF8Sz+hRlZPifTCdaExh7+Xtale
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: c06191fdb04903f8caa668e206506401
SHA1: cb6c285be720fc4f8a3e1b5162e2ef3b4ed7eb46
SHA256: 9ee0a7b4c926c86342dc1f5bb4512ee5433819ea4380a5b530d6473e7568e0ba
SSDeep: 24:iJUbWK6tlQyXJkMP0QW8kc+mPkMzLbkrnh7c9vvORgjO9p0+iCGLPsvrYXny3a:iJUyTlma0+QZ+vqJp1iC8kyy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 782.42 KB MD5: 79019f1731b2974aee27e21bfeb6f7f1
SHA1: e6e8de0b3af5e2c1673fd42c4bbf48c77cae48aa
SHA256: 9f796f5d5de64262d3b2b85047b7bba4d1a368b03768b7f5a8dbc20058f30980
SSDeep: 24576:/6iA2v6GiSSvf62QpSFUE+ZqELWetTd757:/6dfSSvy2QpaUTb77t
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 485.20 KB MD5: f579ae9f228e58d9f5e4941ad519a065
SHA1: ced1e54df87535ca44292cd21498ed42910985c1
SHA256: 5658cd2dcf7f031c4222fa8af3b95e46c908cf98f5e29d083a60f6e53800a7af
SSDeep: 12288:IHkRAWxSN3xW5NPatG/ZbLxsk7LBSKuo2yQ1k8KDUoOn2:uNNednxrLIKuos1zo7
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 0acb04abf2c886c1ffcd94a26ccc1524
SHA1: 8bbaac7ad9045204f287b4cf21bb677765d248b7
SHA256: b5d7cab10f7714ad466883a14aa0f41bd311ed330e659ad1950328de43830806
SSDeep: 24:U93PfO7ThKpDZ6I/tW+4jxEr6L/D9n+1W6vG600vxJ5x2iXny3a:gXO7ThKd5/tl4d5/DVPK9x2Iy3a
False
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat 5.61 MB MD5: c4143c97f45d82b5de1471909b6f5e8b
SHA1: a49384e1252cf76587bb419a571c78676a65cb11
SHA256: 3de00d65e975895aec7102eceab1f3caaac968d76fec99fe416a1bdc587aac37
SSDeep: 98304:Ef0pKGBHTKYzKXH54UuFe1kBpHua/KUKcs3DKVDKurFNGAybmn9m:27GBHTK8KXZ4UuY1kB1iKFKurFNGAyU4
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 248.09 KB MD5: 005e364cebb5b51ca6c408831a4dac81
SHA1: 4b930c33acee053f959d1574f9d35c735bccbb60
SHA256: bfddf3b21c5c4c32778c5bee32ef1a9cb410be0420642479f5e30a0bd4a46852
SSDeep: 6144:3rr9K1Hcbp/XoiTI5J3YckMDIMICc1RuhiaMMMhAQv6:br9K1HwlMXYcvE91RWiJhuQC
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a79c2e90d22f94c2bf695257598f5421
SHA1: 174970d94c77ff9c3ec084067217cbc1bbae2286
SHA256: dd88bb00f4268926d862f880671dc69595caba975b0202ffe19634ae26cf4e6e
SSDeep: 48:L6YR3WaJ9WRgEGTHQKRrShP/BKD5ftDElTy3a:mw3p9EyHhrsPKfqT0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 19.31 KB MD5: 76b3f099378f525730cd95a86c3d6bf6
SHA1: 9aff8a75754555a733d33198f581702619a907bc
SHA256: 0053461a694dbc26f5423569e7d0c3da351137bcaaeb02f4836910fd317f7bc0
SSDeep: 384:J53EmeKd5PqHNBLkR2AqMNsb17YAcAweHfj8R8kd1yf06A/zs17rlXa:J53Eme9faFqftYteLg841yDxpq
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 745.79 KB MD5: 070d3dfdeadf0654e04920c44443c8a4
SHA1: 301c3f935eec5d817e768bcc4ee6529563643f15
SHA256: 9af9ccaf5c54c23b02a544de26407cbe583cdd0d003a22ff9250ed5fbc151897
SSDeep: 12288:v/NwdSGlYzXYOJudEAZPASmsxyZ8V9vXySvgJ2FkKcIkbVSVgu78M6vKs3VtTaf+:9wshIOkEAJASmsYiXDvcbIkbQ+u78MTC
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 7e5542a18a4d21b96ca22e901b60c1fe
SHA1: f089cd7796ff09ef0b261e03c1f938f9436eb7c6
SHA256: f08625f1d013d104ca008415547216f95790b08358fffb5df8931212cd174fb9
SSDeep: 24:X6i4lDNBuhoTG7/2dpmbCBWCGg3qtPWnUU3SBKbS0QgagWS6rE8KcvH/Xny3a:XL4Zc2dpmbvCvaI5SsagPAEHQHfy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 54e7ba384580d34967c392a3d3cea502
SHA1: f4b11056de99410be01d84da5a582d757827d9e0
SHA256: dbf5ef7609d610589867b7d536623e0bf9025f2b3564e45e2e5d72cecda7df8f
SSDeep: 24:kUNHQs/T0NZrreItzengtQMJJR0iEou/pNmhe2Q9cOxip/V276KXny3a:nT8Zhz1JJWoCNmbQKOeyHy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 2559f23aefea8a6ec09f69e65ad82bb4
SHA1: c1496e1247361340966cf788c2789d19401fcf67
SHA256: 67149ab7e597bbc1ed8397c720143146d6a6e37342f1832918475114f36b3807
SSDeep: 48:GvdCFKLrVzGyfHs7H4mFra6ahyHcYqUNrOGM+J+30WK3oqy3a:Gs+iyPfmFraAHHl/M+J+3LK4q0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.07 MB MD5: 23f5e350af65bf50d20e911fcab5b962
SHA1: 9e390c0868ba9c06553799164cfc0fe8e84020fe
SHA256: eb6c5e1415b66ab878dfa5a5460ad67acfc67be08d2ba2506cb63df6919f761c
SSDeep: 24576:Ud8ExwmURziPmyhs5hCjj5JKipprodlG97+hityDK:UsF5hyKu35Jj9ony+hityDK
False
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat 2.79 MB MD5: 3e2a5d4f0c1748687f80df23d0b70424
SHA1: 48271f461b62d2f1d34856a87c4eb30178239a51
SHA256: 15ee49873d76f0a62b27e42fb06dd375d8d85c29284f3545a4d8aec98e6dd009
SSDeep: 49152:oJ6tDuv7GuMRau8yuXQFKUYcs3HVKf3rhKM6rgQTd95HakjyXN5N0Yh:oJbGnRau84KUYcs31KfFKM6rhTnKNN
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 211.14 KB MD5: 57e1303b75012a73a8972a853029ec59
SHA1: b031026b935aac5703976dd2907e70b230d3053b
SHA256: 613d36a6dd8ed3ddef6dd67bf166a92c11b47c96d2b2e70ab1903bdfc777d1ac
SSDeep: 6144:PJ2XzOQEOmTTE2PAkPV6taZpr3J5a6hTimIYPSX:EXdEOgTvlgtaZP5hIYPSX
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: e46d140a2342afb6a972439b5a956802
SHA1: fc09cb5495322efcb6ee1549b7e1108578d7544c
SHA256: 16a55649d8e8361bb464fb435f3428520fef0ddfedd3004076ca71b3eb96b457
SSDeep: 24:IGhbWfr9OpG1r78Iwp5cfInCcC6dZHWi2rgaYkvmmT4+T2DLBxKXx2Xny3a:3h8r9vR8IwDcICcL4H+44+TuC8y3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: e616bcca2811430f959ec3bb5b52af1f
SHA1: 4e9b6e3ea17e35e0ea5414d73a5ca31630a17fac
SHA256: af3c67c555a6a430a5907b0b1c86e74270181261426a47402f2c528a414b6dbe
SSDeep: 48:LFS41SbBE/E1ckbT2OdxVbk3KzhuXgkGDFJPIlry3a:441SFvHbtVbSkhGGDFJPYr0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 335.61 KB MD5: cb06ec6d550d9e4ff229826d7fe3b65e
SHA1: aa5d73aa33d5b54cd2601582de118fcff0f505a3
SHA256: 145d20af135a3751a0180170916356d4ef9ceb24bcce7114a8e0b71667dbfa0e
SSDeep: 6144:llNErbhb59dn7KQU7xkdXgkkQuUuVFGjAsMEmw2jEU5Y/08v/x+UJnMCW/nYGfmG:3NErbhb5jnm+dQkhQU2j/u/0GggnMCDA
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 14.89 KB MD5: f03f9c2f615845976f8bd1f0214eb647
SHA1: c7a342705195a61b6998cb97c49f44666897f628
SHA256: f1d8328a8281feff746f0d89546e8a164b051c291d71389bcdea70115a2d07c5
SSDeep: 384:nWNUjZVoVERDtDQGJ/YTPYHOfzUNgJWvgCiJQ9qa:2SVoViDim0YczUJEqF
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 6d5f78221fb1fdbb6b16c8a0137d9a0d
SHA1: f7886901eedf7957bc89a7a84a64b903374695b1
SHA256: 90f6a1cc14de4506a130f3b9bf6973abef8d8e0d434994f25d53a2ee1107e76c
SSDeep: 48:Z5sRuHTa/tYdYN4TIUXkw2d01yu1LQ1cTlNZ9y1hrVWky3a:+WTa/CTIUcdKz01Ky1hrUk0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 349.29 KB MD5: fc76856af4917fd3d10c71dc69fb1b87
SHA1: 250def7923d23cb5df7b787a7f15fc79eac68b83
SHA256: 7074703694cb4f977d3ae78773a83e41bc0b69fea34222555f6cf6b11d88029d
SSDeep: 6144:Mja2qVVm3p5VeYQLtyLXpYGnSA0LykYe4SPbrMKB0SHbsH+QDGlfOwVXQ:Wgap5lQJyLZYIAykH4SPbrMKBDseQIf0
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: c3704ad205af381bc88dc7c6a3c576f4
SHA1: bafcdd79209eaf58138462ec662b311c522fc5c3
SHA256: c47b1e9c31ae2c719822d2bd6e13bc7b8a2cb540465dec6d4b01a9d1b78b982d
SSDeep: 48:wKwfivZqJu3E3eNRgVJ9J1/SsmgMab9NlVNBy3a:iKh2u3E3KgP1/HbrZB0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 63.79 KB MD5: d7eff6cb4fe1283370e7b415c5c87d8c
SHA1: 3450b16f446d7f4a530cf3329739274caaac4ca8
SHA256: 064029ea35cbd619282146de1237f998195aea41a3850b97ed59b9206120ecf6
SSDeep: 1536:yJLR7LZKQEefFmsKfN8RWn6vciS04XCtENoPnBEGo:ghIMmfn8bthPBEGo
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 81652372cd3b697ddc0b209668098f4c
SHA1: 2f018744c8f4b633c4ab0a1326ce442afcd6e716
SHA256: 48108414e66841698f2f3d32c4941696f5b03067a119aea26bef2f2faf24fe3f
SSDeep: 24:GpcIMuhhXjn9M61RcIzBZEoGcdrlc74eLnHllhlMSHxeIxw2LlfEWXny3a:65hhznLWEWcZlM40z3FC28cy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: d03a0557da687258e61ea1972ec03d67
SHA1: 8e16ea24440615075f875915740ce4792902f4c0
SHA256: efdd4b3fef238e4b4f7fd79fdd334559586b50656142a44f93dd32da2afce67b
SSDeep: 24:J2H7hFbB/f+Mry10I5WsV3C/IKp6oNTZ7wjOdDKtG8IFIEdS3MnSl4Xny3a:4TBy135b3+/ptdxdDKU8aIEdS2SlSy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 9.33 KB MD5: 35cbaaebb95a413fbb30d41de9ee399a
SHA1: fbd5e5140b255e08d658d274e315b637fbc52576
SHA256: edabbc010643ad54376e417ff4840e326a7ee772677e682d83c0a0c2176a68f0
SSDeep: 192:sKcmXRC6ZihamHKwoTiVdo9SdjjXctYKO87YukmrYBFwdr0a:snqCpaqboTiLvjzyo87YirwwdYa
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: bf7ef6bbc44670458649c4401bb73344
SHA1: b55fdbdb535c2623dd825b1c3c32dc840feb2c65
SHA256: 1092f37886c1d81912f0aabc224a4079cd85d81504ca3bac495892856d00313b
SSDeep: 48:xvN+zYwu+9G8GvCN8cuV9KLF/elxQ6y3a:xwYa9GqhePQ60a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: b44aa5268cfe2db120e1252dcd2f8c40
SHA1: 455a7e3775b2f986b785f56fbe0e014744d5ce73
SHA256: a83f7fded1a68c3e8a78769465087d039f0d234ce6ada25aca021c6079ca97a8
SSDeep: 48:kcMa4T3aSsq8uaSdIU14+iN7yO7PipJiiLwy3a:sVDaSFYs/1kUO7PipIik0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.73 KB MD5: a9278a0b016dbffe6f79349906544fc1
SHA1: 6d7690ac2a8cce4b75a0cd3232a576d148a530f9
SHA256: b438a42291eed9da5043cacb542b17eaa39b5c36613ffa329cb822a4bdf6fea6
SSDeep: 48:0DeJmYMQa9qOqcd9Gb6q2SgLHD5dLOIvAUYugqZiT1i9wpPy3a:Ay9M1qOqc7zVdLOIQDuwx0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 3.98 KB MD5: 73f48dfee0ff814bca824c269ded74f9
SHA1: a4b56eb8db0e5911ca238e91c1aad256fb393af5
SHA256: 96f35df94d81f0b679236e62344a0ebb2c662a43fd88a0085c3f6e98d9f1b7dc
SSDeep: 96:p01ePa0HmWXn3gXUPHzQxjK6UBtFZEBouF9uWQ0a:O1CaB23gXryBtLECufuB0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 0c9a73bd516bc1199f4399944cd6a70a
SHA1: 0f690b85304c1cad34ce41857246a7f503763566
SHA256: 2a9beda20674d08e0ec8f1a2e7193df5b0809c22188fcff0cd6471f46cd8c9cf
SSDeep: 48:HaI5rh/sIbuKl906uhDJS99uFiznYQ4y3a:HaIxh/puKl9XuhwHPYx0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 5ea726f5a8b38275fe926c1257305570
SHA1: d8687d2037c58901e88f54339e78c25738cc8d10
SHA256: 685ee4c333e19d7734bdae0537fe16b35c74b3c29cc306783596acad7af4b814
SSDeep: 24:pN+FN7eHTYNF3A0NG8iydbc0Jwr4cRL0u8eVxOh4vQGsycR2gpaY9rxXny3a:pUFN7LNK0NmyJHGPBzfOWYF9rNy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 390.48 KB MD5: ec30cb2bb2ffc4331f03c4535e320e0b
SHA1: 45b3770828915655e997eeba59b43e9bcef96384
SHA256: fc34f249dcb71daa5bfa8fc310e0a9ca50c3d5048eebf57fce1c8fec4c2d13f0
SSDeep: 6144:tdUAYf7A/nqun9NmpJgf23gPZFxWo5ZuXqFTZQXWOFikjvIb+:tdUxf7Mquvmvgu3gPZ7XaXiCX5jvf
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 515.90 KB MD5: 5f98cec65121bb9760ab057c4d999db5
SHA1: 0bc7c46218f77909c3689cb9f04c96149a78e954
SHA256: 8274ae6b36c584ee9bfb8ea7c63f3207858c73997be7a9ee09164f70de23267d
SSDeep: 12288:t9+flBRp39M1l8ThMPHbrW5VD/kC1t4jsxe57Nx6S4Fp1joP4:PUlp39BgHnW5hku4pz0FpA4
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 3.61 KB MD5: 4b5cdaba6bd590fc5f6025f5d2ec2f2d
SHA1: 18f04c2459dbb7ea6e7b58688d55e762b841f440
SHA256: 86d3f86c375b57b12ca733eaadeab81240100e99a547e0cd0b5576205b5109be
SSDeep: 96:qx1Oyye7PGC/xUdz4YlM/MiACV//UR7ikpoVfxr0a:qxGdC/OdzhlfiACJcokpoD0a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: a6a1f93e3bd9f20a14eb286c1f5690c7
SHA1: e7a1ad8d801efb84f2db8f954db54500e711b6a4
SHA256: 7ad939afae11a1f6f2f84fed213b3c94d2c96e5c950f87f553273367aa5dc528
SSDeep: 24:0ebfDC1zohXGTnxvKQqTG5n8qon+bQWpYjAr8fLgVuwtmOZYfXu7tvipgjOhcXnp:TDXhm4InPpCA+QtmOZYPu7ZYgMmy3a
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat 9.87 KB MD5: 6484d8900fd9f45aa14f7847978d77c0
SHA1: 25419fef22d5c2bab0e93eaa19b35cda935488fc
SHA256: a71b67573ba8f7445ed27fab6d8d20cfb290013a4d02562fc89c9b9de7852040
SSDeep: 192:zstPOTrjdhD/GEtj50mZX528UUWB7d6Jbw9lQ83VQ6gc0y:zstP8rjdwEtj5H88UDB7ECgwZQy
False
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat 640 bytes MD5: d53094988b64608a677c1312a9558387
SHA1: 2efb2e451089398e23eef79528da31d4d533cc5e
SHA256: 26db4f1a3afa001128337d4f8b58bfc7febd8f72c256fcb0ceb30c4acd51e17e
SSDeep: 12:MryAkX9o6TTggxMDSbycSU0TkIaDFSiYQxjLq6MDrwihUKguXny3sl:MG/i6fgiMuycZ04DzYMqxwyXny3E
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 9.06 KB MD5: 11486b274cde190ab70dbfcc64ebfa61
SHA1: e5356b5d018f3f2d6dea897b7ce1c4ea05493c97
SHA256: a1250761d0e9059ee4f4c217bce00e83fb6075e6a14158ba04b9fc75c83791e2
SSDeep: 192:i/qjcT2TP+rIsMo7dYbJGoHKy0daoV92lLozq0rj0o:JjcSar5ZdcJzqyUa89zz+o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 14.76 KB MD5: 691205c6bb6f3a4bca1e832db3b83ab9
SHA1: 1b9c2e44300a59a904541c50ab798f00b5909dc6
SHA256: 639e64f4890147801185121ac8dd730309e4177c4a933b0e9a62c4cdb361ddd0
SSDeep: 384:GP6SaO9kDn8Xhd9h8/IiX3U0l7YRrZJkn4FjCibWmoo:GJIsn9h83U0GtnrCibV
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.29 KB MD5: e47aa5baa9a3d45625247f40e606c229
SHA1: 45c3993d0a0504147fdf0f38fb5aa7faa06f394a
SHA256: 1e0e4a47d2b98057441a31608002b6d659cc687c92be85a8bbacbb865234d435
SSDeep: 192:0NKQYeOIAHQpfRvyb1qchrNULjypmNJohLBXvIyA95S3e0o:n/eOIHaqIOamzohL6Mlo
False
C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat 242 bytes MD5: 5097051fd1b1c9b0c5aa3f3d8337c161
SHA1: 1250157b6228e77181a57b294fd82ccac942c663
SHA256: 60751452cf3e32c8108d23f9d58af313fedf01b410a1479cc50c6414ad393543
SSDeep: 6:tLBclQcEyyS5t2t1XzINWrZMxNFV36if1GDrp5CP:tOPrj+1XkNKyXFd6if1GDrpE
False
C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat 41.88 MB MD5: b790da90d0c6c3db2d470430d72b0adf
SHA1: ba28aaf3de47f780fd99f939c6190d4a029b4166
SHA256: 9079e442aee573d221fa746a405405a2553f60de994e7db863d6eb28640df578
SSDeep: 49152:cpSdqU6tLnvVqSK5G22mDgBOOmeGGiU9Erqkbnt7QTr5+Oc2EI+8dd0ZwTse9QOH:CtZKH2mALErq2nt7rvfI+vZpfQ
False
C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.25 KB MD5: 5ae29ceea644f74175e6988483aa37f9
SHA1: 185ccbbd4c0c52a8fa0211c9043fc5c09c207c6c
SHA256: 0e9824d8ea1aedf34637a6e90a50c66467bbe8466f0376af4d27ab8b72314e29
SSDeep: 1536:guq5IWDoqLg4b6lhUFZd0u4TBTpCqMPROavECXmzE9RZaTiVDFA9:gw2o4C+FZd0u4V8qCBvECXyENmID2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 6.76 KB MD5: 79c2fcfe8789ec7a7556cff1014581ee
SHA1: ca78e8fb957735c78f4ca25327c57f52e7271bb1
SHA256: b92e6dc5fe7ed68929d8ebe23fe564587f0a1bdd028198264eed7f70096c97de
SSDeep: 96:tuJFZldV/v91APOS6LImmTDctqnTe9rJGzBQtW6dWX+f/1uM2xSysO2nA0o:MJxvr5pyW+eJJ+G1cX6/1uSzA0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.42 KB MD5: 62734d4a8c0e72d9cb0a13ef3fea9271
SHA1: 0889f92d60ebc8659af755ccd5b697011ad4fe06
SHA256: 34fac87ed699976ef52cae81588cd43d8c280ca0f6726e40b931dcb736a85364
SSDeep: 96:08drWlABYGMVNDmijWTDmkPMe4RrYWxzTtbAge+t0o:SlASGMVNqijWuk0/XpPv0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.75 KB MD5: 157519c65d7dc73970b7ed0abaed1b1d
SHA1: d132cc14b02f64cc449300c423dd67514ccaeb1e
SHA256: a0ff08cf56fbababe879008978dadca9a589d535a5ea3f57a5a8af9c7af321ea
SSDeep: 192:RPxlH92BAbL9Okwe2zUG/nXgTHcgs+VmoPDW81zeU0o:RPxld4CknNYGPXEcxiK81zebo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 8.15 KB MD5: 803af25aa1515106f6775c9e53fc63c7
SHA1: aa39f13c08752ecacf27d82b206a07edda463cd2
SHA256: e473984402b5822182e7318e8601eba226aeaa74b9d4c4fbdb1d5c1a3932a653
SSDeep: 192:hJOOVf3tD8X39M9mLNtfZuE/0oq5ErMNe+NJdUur/B+z0o:yYiX39M9SjfcToq5+MNLJdU4o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 764 bytes MD5: cdf64020483dea429e77d00b42abeeff
SHA1: b76433a55e089d7ceff35aad4264f9faf2471547
SHA256: 70b892c3cfa9e418dbaf52d7a7a9eb80855f15e774973bc037c4bd8c0f3ab6b7
SSDeep: 12:QDmBDuqB4zW85WWDZjhcOWxC2wtZOm57dA0H2XRBfaRcrQcUKguXny34l:QaBDuw4C85R5tYKdA0KisQEXny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 748 bytes MD5: 4de7854e8d579c048e80d7fc2ff004ef
SHA1: 0e3be7b8c43eb3106a62ffc8dfa23edd39b5b038
SHA256: 2e24f1d21133c1f0661b1c787ffed71b205d6a831de60b94f980107da0bd81b0
SSDeep: 12:rGyXpctppRGHx737NKHcA1qWn1eGOQFPC9BYN8cZHHBDWlG+RcrIUKguXny34l:rwp/GR73E7MIeGHPoB8ZnBDJroXny3o
False
C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.27 KB MD5: aab5a7732f926b9fde09ce21fd741fec
SHA1: 25eb4cda5a61ab61c82433b112b6496f366f1c78
SHA256: 882b501be16b707a93497a367cc40889cbd6227f335d221e1a151fb225e2422f
SSDeep: 1536:ojwjJq+7muCWVV6XW3bzspdjkfsUiT4I7Ir4mT/t0D6gF65SzH:ojwFq+7m/98zgw7iT97/S2D6k65ST
False
C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.28 KB MD5: 1f90268da240960f94dc259d81c3b321
SHA1: 2bcd3477bc0023d5bed0db000690106c655f105d
SHA256: 9863811af66e9693882296d9a52c73cc771372cc2699acb0564e287d7fe17a64
SSDeep: 1536:tpKP/VhlTUXR/6PrzU+ydS8HiDN8Qs5z9h1JuLwuC7SYV2AdRdNU:tAXVTTUXRSPrzsk8CRs190+zVRzo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 12.64 KB MD5: e5e5de20b03aac309683164830c562f2
SHA1: ba6760892d9af51ebfa8d1bb777c0a056d412fe1
SHA256: 1b97e83f4778022bdd21697d153c139af45059e1612e9e2f958daf5ce8d21a09
SSDeep: 384:8GLsotmTa5RzGXcLfR9iY6PGBuDhB1ZfHDrT0o:8OTGXcOPbFB1ZfnTv
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 11.86 KB MD5: 214260d3cd5c4d19f517d3f8ade28e2a
SHA1: b40455858c2b3bdd4151caebf00c6e30abdbcfd9
SHA256: 3377a63892534d443dfc97fa7b3a884a12d72b22e0461b0fa366a39deecce166
SSDeep: 192:+a8ZWX8cz+WmcHtkxSJYxMQz3i0fS96xCiMr3JgVL2dVf0833H0o:+fzczVmcHE0Wrm0fSfvS2dppUo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 12.43 KB MD5: de8303803d0fc829da4e97767b31be02
SHA1: f5d1e6e2bebb406fa403ddc8e016a7894966ff36
SHA256: 1b09b704fac90c1a404ea2b5b2edf3fb722b3ce728b2fc9c150315ce48180dbf
SSDeep: 192:TIT6IZkOl0g9GyVQXvXnQkZ7rb1w+mAOmuklcMi/1xkTeqspHrDH75w11h2uz+gX:ETDOOl0hXbrxw+9ucclwspvVyauzoo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.37 KB MD5: 225902b8b18f91cea5ae09c43c3c8d5b
SHA1: eb1cb569c533f326855516415ff02a0165a19557
SHA256: 0065e111a35ebea2591849fc92f362868ef885d618fe9880dec44794350ce637
SSDeep: 96:mY3Jlsjm/L9Qp+Yp8hcNdgL6gePBrbNfZsqNpXWirw8C6cIv9YTO0o:mY3jswKp+Yp8ugL6rBJDpU6cIWq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.31 KB MD5: 64641ec3549244477ebe5d4bf3db9c01
SHA1: 3ae84510cc4779f0f20ccca8ae7aa30835ec9458
SHA256: 7e5e8f055875e686c9b13a71cd882442fce71f91cf1013882dd6b314c751fe31
SSDeep: 96:IuSak6LsKxrsjTXowk7dNlJM/zhElf8lkJ8aBl2IKe3Ny/3H0o:cak6ACr8Xoj7ZJM1hlkOaKIKedy/30o
False
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 MB MD5: b9b017dfb4b794b96adab7e6201a4b8b
SHA1: 1a3b6bc4faf4bf1ef593ae798751310a2495f68a
SHA256: ef2f74e5e839016d3f4a4aa14e9e5b8a34f4d534138aee98d50881a9df2fb16c
SSDeep: 12288:dyZC1slqChJ+3VVomMAcwVWZzP80dHjAoybjbU3GZVO0qQI1/RzVxuvroD7+gJo+:4YCqlDMAcH8kIw3GZVbvI1/R/uvrC+qH
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.64 KB MD5: 4eb30e641fc5c731b18dceae872aaad8
SHA1: 9e6b690c21efc976496d748410288d329067865d
SHA256: cb788816596ff017c705ee946f7afc6702e3c78c937a95e770c2ed0fc92af8c1
SSDeep: 96:tJDGvJw3KUKt9VHpAtmarASu5NeejJpp/+WpWrvg8JZxh0o:t5GvJUM9VHCDMXlTp/vpL8JB0o
False
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.38 KB MD5: d5dd6bc15d581f767161b64c7094aa78
SHA1: 9542512681067e602e192952227424975eb23519
SHA256: 07d1146bdb2b101d77da753723e538f58231956866ee6453657ce3e2ca875174
SSDeep: 1536:2eDP5dVvRCOl+sc7KdT7erKvAL0zoQDnAlgXK0c7Q4hOfBffzc:2eP1MS+57i3RAooQDnAlgX2OFI
False
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 826dfe3981c7a9af3082ca86d7211b38
SHA1: 4dc71c7c2bd1d5012834ec301e32fafc8fe3d5a2
SHA256: 6148e774f80a1dcf49c0b96b2ed736558b9aaeff0bdcc204a434243c5badb87c
SSDeep: 768:xNCHxWKyA1+Ixrhach9apSM7u66VHzECjmxkN+Fji6GcYlUt8GJSti1VTGN6Fs/6:xmdl+CakSIqFol68oxVU6FwNs2fVrk
False
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 1167fee0f261c68581e505840fb1a14b
SHA1: 35dcbac6b0d1036564696f413311727983c01bf3
SHA256: 544ad61fed52e1c05d825cd56cf75b45390b336cbe7f00f85ceefe393b1b26fc
SSDeep: 1536:mSubEOmH3EZMJJrqrRolpLdwrqFOqyHYTaEqs:qbEFH0ZYgRkdw2FOq+YTpN
False
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: cb2eda3e7413b8f775e52517ea7fd7bc
SHA1: 52b8d5b279abbba9d091cc475669441bba94426e
SHA256: 737fb3d70ad72933453ecd61a4fbc44c8d8e52297945abe6418344f00aab9dca
SSDeep: 1536:fk9qb09kFrGlqxTB7f/myslnj8F7x1J7z8vVUB:7iC48F7x1Bz8CB
False
C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.26 KB MD5: 0e954c77ee741e7d719a04336d53c6f9
SHA1: 5f1ecfa2a7fb044f84821b17d3f8992e84fee4be
SHA256: 850bf7f51e530c45458044ce508f40cf446b0bc8a1c015356980c2fdc80c1e2c
SSDeep: 1536:LW8pNOw6JcQQLDcPwtY0hCkHUV4FrLkh1iWZeFIw7q:LW8TtLDRDRe4rLQZeWF
False
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: f10e6378e4290fbbace90c020ab7b12e
SHA1: fcfd94abb1a3c93b192c6b54d9d8afeee093b0cb
SHA256: 3d7ea20c897422d1780549d529a51c7a2ddc6d0c346d4d1cad961f2a530f1216
SSDeep: 1536:HqqxJcbFeW869j+19eL1GfeFjQ9L0B3mloBqSlrv:fx+bFeMKDyLjp7qmr
False
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 89be8fe9449ca8bc4004e5929c5478e9
SHA1: 25ef637edf715e5412f104fa38886d7794428a30
SHA256: 17b5359d25d9a4a3f3306928a0b750146bbcda0c576923bcf9adeaac5442abf7
SSDeep: 1536:O7XavAGmuEGi88dRYyNVT4c7uVYW7bjtSm7V5gQ:O1uE98QYeWXBD5gQ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 2.78 KB MD5: 5667cd86a8cd1c85a4d69882a0dc16ce
SHA1: 6843d1807004ab4659ef97d62721876005228714
SHA256: 71b709ef7c2498ca2c880bdb0a76a9f049a821cd883cbc124047c6ea2bea8804
SSDeep: 48:a/d/n4E2tfTYfeu72KOMlLHXMZg3ULafQT14pJ+KslxuzSfpU6MVhCC+5u+fy3o:a/vdfe02+LQg3ULafI4pzsT7pmLCCUnn
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 15.18 KB MD5: efb28a0ae41718797de6cb461a68f2d4
SHA1: 2736232bd25ad1d3835e89829cda11ee56534a9e
SHA256: 6858eca0f5316f334bb39bcc81f0143d9fb2de5aa8f5d83f28f6566755d97460
SSDeep: 384:l03jUBxtG2sQxIOg69ri5n8ePUxhoGKO1NiPR6K28Ur2o:i3jUtWdd6Ni2UUoZOueD5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 10.59 KB MD5: 842709c5d4aac46732f34431737f756c
SHA1: 26203c63c061952df184aa3060676b4cac6887e2
SHA256: 5b5dbd5116d2c6f629af6324458151a909b7c45c444871ed88e4145f5c3cb079
SSDeep: 192:F/KHBHiZEYfP1xu3fQ12V559vLUcfWnfuvzJhZWOIAnN4Y0gPKgDNP//es0o:FQCZE+P1xuPrn59dfWfxBAyY0mK2P/Co
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.43 KB MD5: d865189facf2d05d01a53a5591326422
SHA1: 5dbefe5e0a5647a431c7202341b532f220b63e4e
SHA256: c25a9a9e79191a7ee40cdcf01a637e7873d95143f87277df9de3b7dd317f7c2a
SSDeep: 96:gWkEImWuZwwWKVycggfu8uoptSUZJsDznu+sF9rQF9cGO3Def9IjpomO8JG0o:gP5mrwwDvgg/uozS0iznOYD3OG0o784v
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 1.36 KB MD5: 1250343d7940876e9cdebd51d82bd4eb
SHA1: eb3c327ff860830931779dd8436936ed8bd90610
SHA256: e0c2b6a8f666a1930cda5763924eccf99545e75419d8f12839bc914ee80bfb21
SSDeep: 24:l5F9A7um+uBIeus8OLRq077RQ4a3fPaH3EJqYx0Imo6D29z8DGxDbltso6Xny3o:L4KmhB3ubOLQUQO3QSZOVxvltsJy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.15 KB MD5: b5b0fcac9c66badbe5e1052d3cd8f301
SHA1: c1e70285e31a20db5c0a34a8cf00d5dd801abd7c
SHA256: e877e388ebe9c8d570766bfe33014079c47318c828cdc96cc18c6bb4feb061a4
SSDeep: 96:BV5Av4kjSe9CY/A8Hclbkop0j8/Cj28BIM+Xd7pXQ1hSgpp43VQ6wB0o:BVg9/Y8Hclbkrj8vMOd78Qz3VQ6W0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.07 KB MD5: 532c46925568c51073148ce5dcf68c63
SHA1: ce50535773beb6b66c2f3984fcfa7b506128bf7d
SHA256: 139404b66a95d771b16b12f8fe539a751bafb34190b97fca549bdfe6b336a0cf
SSDeep: 96:ChGX37GHB9sdTyQx4loreINrKR7SYTCmdf35rw0/4l3OMb9ei1z7ep2Ny5PE7KpV:ChGnIBKuloGR7NvBLE3OMbwuU2Y674cW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.64 KB MD5: 6f550caad0b219c5690f011df19a6265
SHA1: 675399462c3e7df5a97cf0c5170a2391c870e0b3
SHA256: 2dd21bc0ba4584805f7fef210fb6e2c6414080ffae154bdd1cddb74a60c3ee60
SSDeep: 192:NT3D2y4ZSuWZ6/7CKBZDqLvQf6NI4yeSq30o:dX6ZDqLvpIQko
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 8.62 KB MD5: a4ffadcd424e12aa827c8bd336906a2a
SHA1: 5c3d451a0836c37513ca25ae3185ef7384c618d3
SHA256: eba5dabd75755dcb1767d0a47fb6a416366d8be25f24ebdb73a87d36c6cf0695
SSDeep: 192:gnuM6Ne0u4MD6Ko7G1FT7uKrRIMxdwZBVvH+972Ozqv1YbEDDBA0o:WmG1FPjRnz0Re2Ocq0Zo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 13.18 KB MD5: 842fac1b1cfc0bc0ab5f6122545f595a
SHA1: d0cac6418ca5f4f6640813fab5ba6662b73f21d4
SHA256: 313349e970984ffff94a4d246c8f68dd33eb801f165090565e050e5f1988b28f
SSDeep: 192:8E+3r3FJB/ac74PsDmniuFS0+aEvgJXyGS/a29ANNOJTRFR/Wzw+m2fWG4g0o:8ECSi4PdJFSdaEvr/9UEVFRczH4no
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 7.06 KB MD5: c05d172f355b9fbf48befb245c5f1c43
SHA1: c85c6f3449beeaa9df0c17c37a03c6214196cc2e
SHA256: 20864c23ec3e892a054c531d5f86072b24fdeb7b2bfb8c6bf7384b268709a5ae
SSDeep: 192:Ku7ybt7oLOh0QYguWYDlr8Lo2InXqwmUxcsfe43F5DSEh0o:+twg0B8o2IhwsmGOo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.01 KB MD5: 4664e04d7996352d13ecd97922b113e5
SHA1: 2c90c96918afa900bdb0782216ca49f6b7c20233
SHA256: f7b910a1425f39c2841179af145806bb0f635bbe4978f571f3bf7cc55a1924af
SSDeep: 96:/P6Q7Loi4+ns8hJoG8mMtWzyDSNV+bhh3jUNV8hG3vy25v0+zz5SXK98tl8Hx0o:foix8nM7NV+faVoEv0WSXK98tlQx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 9.28 KB MD5: c3b4ba06a00d39beb5b207f6de372b7e
SHA1: f58c001bf4d05b4f29805a3146d0a2a1999c3782
SHA256: 19012c74dbaae87ebd81e1b679544cda712ab2c2a3e86dae51880154479be597
SSDeep: 192:hEr7r0v1hErgLJfW3GIMq9Bs02g78S5Q/xrHYuanTqOt5ILx7wnJtU8I0o:hErXwh0gZbIb9B+gwS5QJbYuavtIxkPO
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.14 KB MD5: e1048434053c4b04d5a994a9b33ac8e7
SHA1: 1fb10e2ceecf48933cee1291b8361d3475f2a15a
SHA256: 8664841c3ec8d4dda0f9a148637eb85272b0422fc9b832aebb48e30b3749158c
SSDeep: 96:iiAnlDjKJMH6Z49m19G0gycyg0ERcAOFZwakEzpgADEVm8ujKk/5JrAu/0o:iDDjn819GcXV0EzNDEV7csu/0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 5.48 KB MD5: c3fdd195c3d972e5e901e69108e8d872
SHA1: eef332d783e8b98de86180c824ac9a1526cf2180
SHA256: f22c87a753f7da18626a586546be52fb8de6ef6f1d242f8692d261c97301c214
SSDeep: 96:QefetVP9z4ion7hkito6nOF74KpI2iYZq1i46wtUzLN6fYyAQzWQdB8cFyKQQBHe:Qe88NkSo6OF74Kp/3Zq846wqz56QGzTS
False
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.00 MB MD5: 98ec39ab775ceed1baab027f468e2c22
SHA1: 658673b55ab260e9e0c75b44f1d863f24e9ece31
SHA256: aef90096455f1ffd868d04f8b23851f6bccf5515fbffbb8104e95b6926db2085
SSDeep: 12288:wCebAfvOqULfEH6EMPN0YD7ZM07rtsEYns0Ia7/FviNxZf+kPBCnCmK0liu+gcni:9ekfvOBcNMmiXY4azFq9frO1s5nr6fb
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 4.11 KB MD5: 02270751dc9833b1ccd60df6272e3c6a
SHA1: 5f1fcc66b646fef3015bc8fde264c110e6aa6510
SHA256: 859f2ece1004149ba4d4cea8f4405be360a9058fe87fc8050ca232a4019ad5d7
SSDeep: 96:x4Nr4a7N86lfjpmYhUe8W1rrp+uMIcJfGE8sbx0zD4IA0o:x4xZpIoUA1U5JJfxjbg470o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.29 KB MD5: ed3ab07863c131e6143aabc871622279
SHA1: a2df191c5916cfa35cf8e12eee81d033b58f7324
SHA256: c518b2a76e202d32cb0209c0b6e24f4bb486743842e46dea54fb5f813dacc2a4
SSDeep: 96:hycM577UGbu0Xc/Vm6aTrutgCpecSbdHi3ex0o:QRly1aTSecyHi00o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.20 KB MD5: c85f3fa9737ccee8035bc362e78b743b
SHA1: 660cabc4854cf5eff399777e4a09debadc9fedc3
SHA256: c420c45e8d18c364195b092e047476a03f427f94136823d6ab4c2a407fdda676
SSDeep: 96:6mI3yw2Y3gMn9uhkWStSKfwpxFLZfNX6VmBToCrA10o:6byw2+twhA5kxHfV6+5r20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 3.54 KB MD5: c8e427d86e2b9dcf9549c8a4822276b4
SHA1: 1e164606e31f8416aa755f275a8b162950cd9c51
SHA256: ffa2330aacabbaa2477dcc682106ed2d8d6e07384e7877202efaa376b917b4c6
SSDeep: 96:MDCHVYxAZRaJChsaf8OjkHMDVuz4FOQhfMtIE0o:MWVSAyJClDLeh0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.86 KB MD5: 249f2cc787300f0f53b105173d2f146e
SHA1: 3853a59b0c3c03129e5319092d930547c15a7f2b
SHA256: a1b016113a42faa887a948480c666ea1a63d5be3052c562ba9426c33014ecc38
SSDeep: 96:fC0QoqeFyiAumO1toIq53DmqwpkaOHSszWRnfY4lxvZ4XyCl5q0o:f7BRyVPO7JOzuSv/yn7vRCS0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.79 KB MD5: 5613a6ab91fd3908da25b35af9ff93f9
SHA1: 9ccc87acb9a0c63763c4bf8b4ce3ea86f3b44d21
SHA256: fce0f952f3b98733eaf32793ac7b88ab8244071190860c7b9d89ebee1ae18828
SSDeep: 96:ayEL8g36hLfLSD8+n4CyZJHmqMY1jIuBjnIs20+aK53UB8vEAx/t7crgHFb1rAyv:ayEL53yfuD8+n49GlsjxfyaK53UB8wgt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.34 KB MD5: cdbb96cbf884171015431571c3ccb2fa
SHA1: cc5b48f88556f737a35007e8241be87c3cdbaf37
SHA256: 093e08fca493cf0854e9e952804ea4da8890d974108f3162c7f6e84a258bca4b
SSDeep: 384:T4OVSOe4dxyycesukA16np7C2YTizpKCQu5WaDChJi/8BKVRn7bBo:rVSmdxyHesukm6l1YTizppKP4Hbq
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.32 KB MD5: 1c4bd7c2cb3b26820e8a2a05cdec3478
SHA1: 307443228c9ff411eab5c13dea4b2f735db9a693
SHA256: bfe42163f0fd477351363c8cccdd5c2c6e4588efb5c26ddc640ed1e98670fa7f
SSDeep: 384:XszROHV6SFEDRjg9zBaCDsY3y5RN7mrvo:XszR6V/FEO91a0TuLSrg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.82 KB MD5: 9860f6a1b27ad503120cf95c973fa99d
SHA1: eccaeb738d9ee7e5031f5998dfa5462c0386035f
SHA256: dbb4d2dde760cffc8ab926d68dd7d5dc247d21652135f9d41b81b3e73b1d0160
SSDeep: 192:8z/NL4bNRAdTGiewnhhPy8UVsK300jf+vP0A/UagUAQc4UOF+VCDifHl6Hde0o:MNLOjAdTBeI5kp30OEV/UagUNc4jkyi9
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.15 KB MD5: 8bfc07f94d104633f4352822902428cd
SHA1: 91c51f11448c812eca451bc074e7b0cab7551f8f
SHA256: 745b7f9c680c2a6e019e17fa02877d15bd58436e54aee3b0359494be1aabcb16
SSDeep: 192:ryEughM91uTOZF8RvbYARYs1hk4dqzodscjYp30o:u4UtZ+kARYs1hk441ao
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.03 KB MD5: 0c49b4a7d85cfd2ef30e80d086d4d06d
SHA1: 212407289ae0669c9d574147c6b9993c97e0edfb
SHA256: bdaef69c211844cb835c362c767777f8231cfd2897860d1b56ff8a4789821c59
SSDeep: 192:h7aaMpAATf6TQcyGUuoGZYflBnCkuYz+5iXMwTW064w0o:5aaMOATfKcvRnX+UXlTWUXo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.03 KB MD5: 46ed541b01ffd2b94e5ebc5c1b4fa690
SHA1: 3a063e7b06ba62ffbfa1130ef3157b00ee0e8bcb
SHA256: 49a6a6e42bdf40beca04dc9759eeee0ed483dcee7dc91eee511f473f8f7d82fb
SSDeep: 48:B178GyNWjB294y0xO8rRY8YsWFQZcaD0kU8Hc4ovQry3o:6NWjeaOlAWsc4uC0o
False
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 51e5c5d29682b52edb4a322d4c7e8519
SHA1: 23bb554b191cea321d43f8fd4b2c6575a20acc2d
SHA256: 2182dc69c4de93ba8771a051475208bde32cb00597f844618b94a4d026db5944
SSDeep: 1536:7hka7TqEpVRLL3bnW9aGatMCi6i0DatlSad1EaEVwfCgv60tU+N:dkav9pffLnfGa+6LutPdybaVD
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.79 KB MD5: ef29ddfac258a42065131b6a4f2112e5
SHA1: 1d6803646dedcc847843f70795a21a6e76c578b2
SHA256: 174cb3d8ba080137756d9a14f58192609074eceb7f3c19d4ed8098357a295c07
SSDeep: 48:Jl/iFnBLyaMmv1Y1ZUWFOV16Hao81xjuMD51hcS4ly3o:rcnti91/e16Hal1xt1El0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.90 KB MD5: b7fbdcac10a9ea4f8dc1378bfa33d63c
SHA1: 9215968b281dbde817543f2c1485781c6c689c6e
SHA256: 34dc972f526792bd555ca97fc9740729eeaef40e91213187d3562f2d0a9aa535
SSDeep: 96:YkoGFG47R+pmbweNAMuHZm99OSJxAxSHDMVvuygVs0o:YTGMKVbweNAMUZm997znAVGygi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 27.45 KB MD5: 46b227f39361a4cd3b7cafb00b89c93c
SHA1: ee28e20db2acdea799332b26df0c712ce2eeba76
SHA256: 4100dc32592b06ac75bc04cd61bf137b40b2c647363d12af009946e28279fe31
SSDeep: 768:Mp3Lsh6U2uqmpEGZtq8w4gXF/nw4876YlHbM5kllVeEuif8IEUP:Mp3LshwsZtqaPx79O5IlVemURUP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 25.95 KB MD5: f1f714014e36f13e6639fe2342816dcf
SHA1: e47ff1bfb8bac8586775c36ed75d772600378926
SHA256: 12115312bb8c97318299b5f088c133ef9a00ec0dd95e1edfaf5a71f92ccbeeb6
SSDeep: 768:uWAGeWJvGXcwUgeJxsmhsYe0wSmeRC0Meq4KWzw+2W+:feWJvGXVUjzhReCmDT1Wzy
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.93 KB MD5: 281e55d02a8e7ab9eea484a4e56d2b7c
SHA1: 43438b8b0aafeedcc7e892db95ad1bd7ede399b4
SHA256: 7a3c49cb6140eff4d232cf0084b9f3606606bfc581409af4b972a695d6967057
SSDeep: 96:KFLYShbkQu0d9U6bnzy5JiZanrp9eJVsu38qlxw6SJLJSl9mPhULq/760a1QT50o:KFLYShIQum9vbz0QZarp2su386e/dSSH
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.18 KB MD5: 5fcfee9c608fd9d01ebbee7e17233063
SHA1: d3b8f7148f5c3d3bd1c733debc1ef5737fd568e5
SHA256: 40011f7c29dcfecd8bc090235d66dc200ec5c243fda5b38e9fc8139d8de6880c
SSDeep: 96:FK9V4en2XKJODyapF1YqZKkKmkl4kiH603D0o:FoomsF1YqtKmkKtz0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.43 KB MD5: f4bdd0728b16c3ce2287a4517305a69d
SHA1: af2e15f9c960d3603b4740bc43b4fae26012dd2e
SHA256: a4f9fe2515de80d989003010fa8c57e69b49ae31992343865cbae5a977972a3a
SSDeep: 192:4W22cNQj7EVYNqPZDebNqobmzlwaCUWrFPo2kA0o:4WhxjYVfPZDoNqWmzlwnUWre5Ho
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.61 KB MD5: a22922badd90e843c5461dcbab977307
SHA1: 07feb3be4a10ea3db09ed8d390f2265092a41167
SHA256: 5c7d9e5253ad0f91e489821c9e28653e3499aab3e20077e7e24ee4b727557f5c
SSDeep: 192:dclj49crwvnTxQv8R4khaU9eR4pW8TZ0o:ilM6c6vG4HsgKio
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.71 KB MD5: fc33bfb364f98f4fa17058f49623eae7
SHA1: 0b6f75c193e84159ca1685a2e6249b6d262feed9
SHA256: 767772f3f7c1cbab981a077e379098912392730bd93211c5f648c364f414df77
SSDeep: 192:mEzyLHDwTM4UqpdSM4dc/WTxbz3iRZ3k+UDgvxaLIb4yye0o:LkHDwTpd0eKxbY72gvxaLIM/lo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.26 KB MD5: 5c4373e0bbc6ad9a4ee589bff3d22bb5
SHA1: acb5732e402196c91f745eaec3cf542cb9778b77
SHA256: 66f4d8e20f83f29a4962545efa7653e50e84a5c29d7152838274b31002f2169b
SSDeep: 192:nFT9Vycj/Fz3U/s1K2S3TxbkmSxwKoC867/KAWQSj2Gllbdw0o:FT9Vyqtz3BhS39AXQ6TVWhSGfdXo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.29 KB MD5: 349a9d886c20be1ee3aba35a5da72f37
SHA1: 9424a96fede23efcee980b1e8f83c1e1642b22ab
SHA256: d53e13651c82a105843dca33473bcdd6be3ca3878698c030aeb552c673df944f
SSDeep: 48:iSbR3s8q2aiK6ALDr6Cm6PJIYhpe7GUkcvg3yle0nkujdojB6WmrnRGzy3o:iJLi7ALaTQS26kLiM8Fo0WmRGz0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.53 KB MD5: 7b3144956079aed2fed21d87ac60a1ea
SHA1: 9950e64492d2bca927839fe812a745453161bf39
SHA256: 9576158b7cee7c15be2cc00105b339fa09188256725cb2a3b2b63198605e14db
SSDeep: 48:0mY8x15bhHKkwYUjPdM5CNQlZ+XybVPFgxBeMkXioZnPafHy3o:dt151HKkw3jPS5aQlZ+XCpFeenioZPcP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.15 KB MD5: 30199afdaf83b04e96adce829fb40b57
SHA1: 4c86cbfd479c34f424d10f210b450efb0d3d6e6c
SHA256: 6b0ea5ff269ee951b0eeca3ec9505dc89487154a08a2cf91dcffdb9d21e5cb4c
SSDeep: 192:GaF1oIYEbjWADDVDH4iShODBiWtk1kNL4e0o:GawIYEbiaDKxoliWm/lo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.71 KB MD5: a48992d4fd90444fb8920dfefd1f8bd2
SHA1: 69ca53d8965cd01920f4b9ec1662cad7b15266b5
SHA256: 94e93d8e6e4745ed3e2e6034605aeea19ae41cf75db716d3e60318991b2db93b
SSDeep: 192:BhagwVzA9OR1ZBEDc8/wpi/Efp3/N800O61Mu8vR80o:H/9O3EX/wpiY1m12vdo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.75 KB MD5: 2c355255182176230d879fb32f9c81e2
SHA1: 05ef8c59aa105d40427b3aacbbd3681e60f8f931
SHA256: ecbc949a26e54e8d249dbd3b0e0d0aeb794656c70198dea61d90c94b201d63d0
SSDeep: 96:VKL+l6P0L1vEikiQ9SM8NO1++qUWZpXzusgLjnNqqYroSNddZrxJyauxm5M0o:VKL+i0pkt9BO2FWZpXSDHnnOoIddyaup
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.81 KB MD5: ee5a52d70060ef8dd5b03d33d543e504
SHA1: 76443cc834fa75fa81d8c348052607f89ae6e5a5
SHA256: 806da6bf4fe3060210eefc7723fd02048887d52b6995888640bdd90a915740cd
SSDeep: 48:72AZuGzcFvsOFlhngS8SQIVrMAAt0VGK4zo+S+nAX+5sCVoqf4Cgc/dTWUyy3o:75ZuGIhFlhnglSQI6TtyazfjAX+WCaqg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.57 KB MD5: 58e945983fdbb254bf88982ba00e2c9d
SHA1: 4a65c06584fb9536af6fc12506e6c1fcf78e5dc7
SHA256: fa4f484d737c29849a5a042c8f08b1803d222a08f630746d2270e0822b341e69
SSDeep: 96:uP5ni2/7CKXggEkMS0OKvUm43PJdKJlEQrbvg0gUeAKDJoZp7LbY/R0o:oV/ZwZv3WJdKJ7vg0O/DuZp7vW0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.53 KB MD5: 35976d4e6316a4d27fdba6371d63b779
SHA1: 6d94e3f3bc60b694abf3cbf3dc63820b47dbd372
SHA256: 3e76e59da5a60ff87fc979f28a9551c0592aa7c9fd402c1423334b75577079e2
SSDeep: 192:vWOEB9isRWYXAmbdyDAAhNygcRwPo4n8pP0xermx32Evh2/40o:u92MA8y8AjymQ92EM332/Po
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.73 KB MD5: 137c72ae0c927d32f18d7a70186c83c5
SHA1: 63d96615be93f8709398207fcaef83b18cc63cd6
SHA256: 2ea5173780fe113224f7b65abe36275b309ebe906bc3b8989d00e4caca42df64
SSDeep: 192:bJwPy1sTaRnBLFUOssxxYicGDfW1XOErpxJhIBhUbQXEpxaph9Ok0o:b2K6TaRnBpUTTxWW1XOE5hI3U7napbOk
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.31 KB MD5: 65da0108d37f743eb2d8de7a52ef744e
SHA1: c6d2f5886661d5f9fb4dade801ddba6c045f2255
SHA256: 889f749dfa3595a3f6caae9fc449f1b9f243365dd1293d2bba704c59c2cae1ba
SSDeep: 96:QX/tv6Bv38X34gcJVPGp0sBt/ojWNK9etbyKaTNXjnTsS0o:av6m3zcrOmsnQS+a1aTJAS0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.86 KB MD5: ef355be6b61ff5634ea564e82300ad28
SHA1: 69b8f409a879c03931af6ebeb32626fb379f1c6c
SHA256: fbfe1c94410d8825c03ee0ed4c1a12e206ddebf149096ba3b405cf42caaf5a7d
SSDeep: 192:HdfLGmCvbvEyfIxg4ens74JWi7zXTiiX0o:HgmCTvEyAxXecylEo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.86 KB MD5: 6a2e696076426f819544f8ab03310a62
SHA1: a532677a82353edd2afa96224934136047fa7aa2
SHA256: b37ed528f899e3af13254adbdbf5cb0ba285ca7bfd998ae0eef4893a5f2c304c
SSDeep: 192:bzzLaNkHbqBlUvaC4vIOMYQfxk1hfMlbko6WJWx0o:PzLaKHbqB4avvIORskqo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: 08a9ff2dc97728afa69f1cab26de7edc
SHA1: 5110dcd3dbc738dbe1fa579af38154cdccbdab85
SHA256: f7483b719da9a1eb437c0b6aca2a1c3d7c66b16e35a134fb2f65ff826fc16f5e
SSDeep: 48:gWpzfL0FSyB4nEWGtqBMbsBKiv9VDLapd5feRCy3o:gWpT4hi7yBeRC0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.67 KB MD5: 3ada0002c4996cabcb403f3114acc2bd
SHA1: aff4a79c2a03a07a062c9d3def6fec3e4f1807d4
SHA256: fe34cf26a0bd18e11f180ef7b94aff366b4066115db9ab39041f366861655601
SSDeep: 48:BPtvuSbO8/1yX4iSHVY2dFwQpHFa15kTl1kGRtdOp9yujqN+AbMOIN0cyj16bBVc:BPtmSt/cFCb7wc0aTRU9ydQAbMJ6cyes
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.51 KB MD5: 4fbb69fe4aa621afaa5bfe81de91302e
SHA1: 947c242353c222cc0c9465f023da7d61f32299fe
SHA256: cafc04fdd2cbf5ba36ffa7ec517d13b12d409dd528c912132406b5e14661a665
SSDeep: 96:H8MUcpPJKin4XaSI9SeONCB3qUIWo1PGfep3j8J9Tu0o:InxXBI9SeOg3Cwi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.39 KB MD5: cc9a7b5e7ad3fc0c5c2a26ada176f108
SHA1: d062997397f82be2e967174dd37b373ca9b7939c
SHA256: ea009a7c00bd4f4d9916e8f4e3c4611c40295f4a4ae152513ca160be0b7c388a
SSDeep: 96:Lh1qoedbjP9jKZiXLzvikOo1ym/jUgtwQBExwYv3WRXA0o:LhUdbJKZc3vikv1f/jUgtw4ExwKG9A0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.12 KB MD5: cf378b381ead3f4224f3aff8e7e6a2fa
SHA1: a1ad7cab8cf74a9882c200c3722e72dc4da999c5
SHA256: b1e4608a0e6febbbccb508115a06f5a46520597d43cb1b267bfa911250ae581e
SSDeep: 96:ng+LCA7VXcXcR+rFRioL9hljPTMcbAUf/QcoXHs1a8arQV+nbIvubmcdJp0o:gBMeFsoL9nMcbAUfbo81a8assnbfv0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.12 KB MD5: a221b789c6e8a1161d424143c4343c8c
SHA1: 5704f4e97c35d41b1903a6dd0ba596f9c5f2ddb8
SHA256: a3e65ab4c5f6ba6bc0b7abd7844c3d7db784095c6bdb33282c461368aa1d89db
SSDeep: 96:+eDzg9PG4/4EzU144kpDF2L1Q3HZTlirBhMjMipvl+Zf/k10WWA92lom+gN0jA0o:+ensu4Rg1411Q1Q3HZTlKBKjV9+Zk10H
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.93 KB MD5: 5f5dcd93839858dad981c8543cd0e725
SHA1: b592eba0c86a343fbc4efe14e51629d96f3e891e
SHA256: b570f760083202b2409f7768b28ebc52fd6f6a744791dbc44834daeb309c703e
SSDeep: 96:/2nyzvXlE8/uB5IXtxmAjQRHZX63rgTK5A12nWahoaZl0o:MyzvXLiIXeTL6bWKaGWahoy0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.50 KB MD5: 668898c042b43e2ef2f51a6d5f7893d7
SHA1: 2db00beb22e18ecdf581dd4ffc312afab7370a2f
SHA256: 14200375edb66f6eab686d295fc7c1c5af1d6a3fb904aa8724fee78ec4d742e4
SSDeep: 384:oOkmEtgH0GiwwlGlJ3foZEFuGPZSHkaCDbPYzW+uaGzZg4xPtqtXhjWo:ZkttEVihGJ3AEFxPgHOrY3gzZBxPtwBZ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.51 KB MD5: bf278e5bf4f8f37e218836892630296f
SHA1: ad58f3377f3dd29364acada074501fc56620b53e
SHA256: 5172dd2940f05cd92e541bf07f31b04af0d98762ce856cada0e83ba36f6ba997
SSDeep: 768:2iNx/RQ0fkyLZCFWqhhJuGyN3womfYJVPu9qp:2ii0SFWa3bd8VP2c
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.61 KB MD5: ca124e66300b9203ab8be710668369b1
SHA1: cdf556b3bba890e711cf4a609050702d1d05a8bb
SHA256: d54ef3392d1e2781f1b3a267319ad78c2123e47c616976ba2275e6c6806cc570
SSDeep: 192:K6iwPTQrQt6figjNaanq4ZPu+in6WR6mt//LV7HDlaFzst9L+GmtpnZW+G06ovvR:K6dt6qgj9PLin6Kt/LV7jlaxs9LZmtuE
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.00 KB MD5: 78a49b10fee2d6d91dbd399dc4f92a05
SHA1: 8c7c9de0fa5382b0268424ed27e68a8cc16ff9b4
SHA256: d45c8e5037d7111bd800841eb17ce17ea1fdcdbbd93a066e6b02a3ddd98f079c
SSDeep: 96:FeBRxenE/LdmDRmq0ZFlQSEmDIQDc8rJ/4yn9JcOmHs2tnjASfjy43G7UHojETrL:ARQnyLoT0ZFLEmDIH8rEs2N7NG7kojEz
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.07 KB MD5: 803d545efa73496a084f390ec170e63a
SHA1: 533d8cc2827fa015e7e25b18cab4876054e3b394
SHA256: c70d7178e3520f2b89d464b353d189f5ca960d4d95a72144d84109cbf3a50af7
SSDeep: 384:ljKhOzyjTNTxKw3Qr5PHDcBw6L0vIWtMNlhRP6VFh4Eo:l+hOzy90w3whHDgZQ0/RPCh4/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 16.53 KB MD5: e13bacb06d62a8840bb6d62ca9e2a118
SHA1: 76db8cd78ed89145774c1a48304d588a23c4a64a
SHA256: 296d88d4779df6ba8fb9345728ceddacd2a5c3e4bd27c8c11e085ac354254aab
SSDeep: 384:3EJ08g3c7FmeAin+NFWTwsF2KZgjnlNY70/r0yo:3n8rBm7Xe8HTgd
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 15.98 KB MD5: 401ea7e0f133f398d42416e9b89a0843
SHA1: 36c3d2bdf41133d45cac91306a74ac31bd910eef
SHA256: 18c3fd2b84c2b2f858e30dd3125b59e386d5a6de225117c74dad84a5460daaf7
SSDeep: 384:j3bIIjT03HBhpIIu3JP5MesvecxvckapYrdHYeYThIlFhb+c0sto:jLIIjT8XIIK1Wdecx0kaiEhIzT0h
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.36 KB MD5: cdd9d0d2dcf03dfff505e24bb4d2ba72
SHA1: a13a9bdc1dd75ab479a83e174e7461a2119691e5
SHA256: c374e01672cdd3eedfa4df00e688e15ad441fe004ecca572d844970ef63c2418
SSDeep: 384:HPlxQ1seW9yORnKi8NL0ZniEjTH/NhTEeVjPLLgXE+WHhdglZgtd9XwJpcjkhM9q:vlPXTnD7HX8nohjgQkO9bs6d8
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.04 KB MD5: 88b20b7867fc31b80a23f407e548765a
SHA1: 47abaaf567a8dba5f2cfa69164bfd458dc8bc312
SHA256: 1652339a0a78aae7c096b50952fb96c446f2a4d13460430a0f97c3cae16f6c64
SSDeep: 96:rv04/A2wWd3YYk4IyG48OYe+6EFSGpT3zmukAkyWRktymgEMvAs0o:bLd3YYmAYe+gGl3qBFNyMYs0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.21 KB MD5: e6c4b4affd2a3022bc0a53589a8e0d99
SHA1: 5d8c3750673a23ca89c2cfe82ff43a19d2f22b3b
SHA256: f7cb7af7ef8d3b862598b2de5b686104809b5fa44c59dad459562b3f45eca10c
SSDeep: 96:eJjg2RLmOrRVkHBWSNDbagzLtolJ+mgoxAk+EYj3V0J0o:Ag4iOrRWgSNhzhomSmHXk0o
False
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: c80a4fec9c04eb6e99fdc5001bf75254
SHA1: ec9e37aaa4accdcf9ccec7286ff04824cc7c7007
SHA256: 40a4e404ff69ddd94cd785752b53a06954e78bffbfc78d5b0de6d306c719747d
SSDeep: 1536:QxZUrKogxu6rqbo5ZDNg97/iUJijI9X7XDSH8pUuW4cj:gxuPbo7hE/l8ji7XD48pUuWdj
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.43 KB MD5: ee515102fea44b401c83e658150634a0
SHA1: eedd7843589f4c00b379f8785ac172cb7a9957f5
SHA256: 1617a9b0ca76f9160448ad474642e4a5cf4a65bb207d117b338d1875cabc9069
SSDeep: 384:lVPqG006Zq3KK2Sn7OI/sgFyOf4Z/q8XO6c60m+cpgwbPqK5k+eLD/LvqgSzGXZo:l5qGJX3rPS1gUP7OVmq0w+eLDLqgSyC
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.00 KB MD5: 35547d81c882de02946695c8ac0ace7f
SHA1: 670c8aa2611b774443fc367a87a8d32359c2d5e0
SHA256: 0b971347d62a7f31d5ed7d93e7d10b9c9bd6ad2bf8e853d3829fd9940f75f8a3
SSDeep: 384:znsQUK5ar27Ot1U4/rsZrr8JEHp4fiR+qekadqpo6P39GueYmhFeSxXQv0qZ5vRP:znsQB5l7K1U4IZv8Jop4qLekFaTRXQv3
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 47.11 KB MD5: c5bbc01bb39cf6bb5752cfbf068ef7af
SHA1: a834b605c60e801b4107ccb6d0fc68ac0d6d044c
SHA256: 3980f6d613c083c92818805a58e231ccc7d42a52001a6f993f398b1b17768fac
SSDeep: 768:f9rJCreysRPwt5UlgxgzEuO2czmxg+abAJG7TLJ9kHS3hjrBpoNq0fsaWIlw82k4:tUazwt5URXO1zJ+aUGn53B1poN5NWIlS
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 39.50 KB MD5: 45a46dba4f6b239ae01d6e11505cac53
SHA1: e9ebc07427e0689742f9e1c9597858294d1a68bb
SHA256: 7ea437dee63b3e906cdcaa09d7148c6ca3eff86c483a6496d3396dabb9c23515
SSDeep: 768:Vk3T9bcJ3tjInS0vqLjTqIGZm41ZFK6Zxj1ea4WbCBzlSbKh1c19DnWKDOb9jvVB:+3TqNSnOLjTiZm41LZDeJWbCZlwKh1lh
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 46.90 KB MD5: c5c58b002037647e8b7c47454847c0aa
SHA1: 81af9de1d25eb123e4ca15f0877f81140c9ac2be
SHA256: 0d97e5d8375f68562941204c3e6b11bfe17a6d10141028b2104041b66d35ce5f
SSDeep: 768:LogapygOJeDE1ZjLhSMB1OUyOAl3MF0B5n5I7Ki/cnWjh9osxntnCU2hd:lapycE1NLcMB1al8F0BbC/1osptnKhd
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.43 KB MD5: 24f2203f86104c5fae3a7864bff6b02a
SHA1: 4c72ec06060102491e6c96324db39991eecd9aaa
SHA256: d0e78615429a7b59f38d44b841e5855e728b07302bf2ff0886170b0d7518aeb2
SSDeep: 384:qyMyocJzKNSDk38Cj+rgW00OYI2gkUP5gNU6kIBix5yEm9lh13qFo:q3nsUTjwmYNaOmUsOLzaW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.31 KB MD5: dbc20fbda3e98529a064533693a10cff
SHA1: c7c90027f37111eb87fa108dbcf9cfbccfcedb1a
SHA256: e1ce36cd1b8d36910a82df3ab18b64152c5352784bce4b5028a6f058240ad0ea
SSDeep: 384:22F5sGiM87gL5tazIFQ0MUritpuYFUQI6YNTRe1kG+7DDjLmMjhjJ9F6o:NXsjMYgLIyVLriPX+tDBRxKMN
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.01 KB MD5: 0eb720b3446b6a76183dc905faa9ba11
SHA1: 40da3aaf3a8f02cc1e6874dcbd70cc45d171b4e0
SHA256: 74b547ba83c2651ac3ae338724bdac0aab0f3cb1cd886d0f3a59f3ca07d2d728
SSDeep: 192:9SW1YjKIx0yP4l5SZt2GM8lHspKq6Tt5YaGBuCrfOFxFxFoyZcC8eIXYD0cTguhv:gW1YqyPKd8lHdp6BuqGF4DCNIIgyOo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 13.43 KB MD5: c969efc6c37d5ddfa1d7aebc69755880
SHA1: 82b1b75801baa7fdc630480c6c1a28297c6cefae
SHA256: 2c6c30237d22cb3ea1d65c6d85dda1e8fb22617d5b4944bd344f881660bbf9f6
SSDeep: 192:jktd4/AEVTPrKGqoKfJT9GwIknIV+XGE5pA0JXDLe8BiUubNi7tEO+/cMcXLw0o:jktuVuLT3IVpE5plJWuLqNirMQXo
False
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: 1a8061768d31bb0bb97b12f440c7d95f
SHA1: 206b7de7a5c61649d535fe5bf2170c7a5c3ac6a3
SHA256: 6636b97e2c2ddf4901c9d4ff08025cdad4acbe01442a24da4012db10c48d4531
SSDeep: 1536:ULDv/dk6gBApP9hXpo3/r1UzouW3SSOVOlDVGBftkz8arRPiJSYmGT3:UL766ScFNqUsbSStVOftIrRPioH+3
False
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 40dc78a70afffc784eb070aa72c0edda
SHA1: 4c87d70249d04bd6c1517949c270dc77d7641ae1
SHA256: 226d8fd11d0d81f90dd899519702cf607c80979f01728481d7e73377f90b1351
SSDeep: 1536:J4r5XA/RBcezYno6jH3lnzN/DOzAoH3NR6b3MICs1DG:JgRijTzYno6jVB/D8JHdC8ICZ
False
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: a18f5a9609827174ab55341eae4eca7e
SHA1: d9dd49b390390b6e6dbe0342a08c684b1a7018c1
SHA256: 58119cf15364501a997ebd17cd3b0ec7115e2266fed685188f8690222ca25a34
SSDeep: 1536:iH/2AGTY4T/OFl50IWvcnDTVLnaYRV0AyBRSAVSJ:if2fY46T5/AcnXVLnakVCBvSJ
False
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.35 KB MD5: e9dd87579519bc88c95ccb55511f4a08
SHA1: 5218b30b1ff0a09922fa8052fa5d47a87dc17a3e
SHA256: 538797c91bad99750c9d423dcf8915bb8c289b2f9c3bef2223e1da0fdccab217
SSDeep: 1536:0lFboqIhogcBaz1ApuQyj0hl4ZddEF7JzXKmEulV3QY:cbo9ogcBazupO0h8dg7JzXbEEVAY
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 16.04 KB MD5: 3e07a1527ad5151d29aac5406c3efd87
SHA1: f9c397e0966061b150fd5282d5d6556c7a988f0a
SHA256: afede1344b52e95f59dcc38fecc50eda61fded80cc7e082ccbfea0329855f00c
SSDeep: 384:xNyQ/rs/oJ5pR3XJj9MN3rhhYM8x0YNlLViVXatRo:Hyh/c5TJs3VhBk0/VY6
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 20.21 KB MD5: bd6113266a64589513801573ad3020ea
SHA1: 79527468cd8c2b99565149812d7a7c45e60a6efd
SHA256: 415e22d905280c2b190b0ed0ee215071374ecc99376da6db836611661bf82628
SSDeep: 384:Fi7CQAiJAQByF/wGa+n+YIG1NznRwRaRyYj2/X6o:FiPF8N/prIAznKsj2N
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 15.61 KB MD5: d7363ec7aef6c1b15ae4fcba684b8760
SHA1: b9dced5a6b59656928a1ae4d786fd8e07fc9dbd9
SHA256: 92068ce79c3d2305fe262f0be64de7a5a4798181ed2294f294a12e017cbe32c6
SSDeep: 384:n0+VXZRhpMHn9LdnYJh3jeAs1SwAaK5VXdUyVMgcuBOEo:0+VXZRLSn9BY36KL5VXdjVMZuBO/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.92 KB MD5: 01601cff6b4a2eb8a343817be2425b09
SHA1: 9449d3eab4a477383a4e23e537425d6fa32ac073
SHA256: 9a49606665af4373959ec986271495c541fc83d034b7bd4aee731c314fa73120
SSDeep: 384:/CGRJD/kCH/tTtodvhOE8wyTh4RlCrQIpgC6o:/9/XHodZOZwchHzbV
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.93 KB MD5: b764bd962f70e20ef4841bba2494aaef
SHA1: 8da8c4c50752fc1838f7466d8983348a25306668
SHA256: 4c229499b41736b676be87d0b8b8f952380564686e9431cf74a20ddaa5bf35db
SSDeep: 48:r5nClzowsYYTaAz8Rb5Q/5khzW/Mf/WbkXz1RBdHWFXbwl2y3o:Fnezo60aAz8nQRkh2atRQ10l20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.71 KB MD5: bfb2b71ed24f116860f5f3756cb6ab89
SHA1: b537522153baca2d46fcbaff5db36e298494d5fb
SHA256: 135162e954f82e570d7ca12bd1a019d7083d89da67b591b89ccbc3623d21b0cd
SSDeep: 192:CNbxKYtAZBn29ko08sO+h2+bA8pLRMGV48B4rP9JFdSar1XQe0o:CJxSzhoB+h2AAKaGOO4rFJnb5XQlo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.81 KB MD5: 3dbbca4b246ba563189ad024163806a0
SHA1: 61e49cbad69ec55e6caa72d0a75d2123d6b594e4
SHA256: 8b0289f8324e6c0e214243ef965006a5b6d241191ccd66657d487b2d026e15a8
SSDeep: 192:B8vqErXtLLW7rV5MIz1PYrMbcFts8ol1OUnkqDJqe6tlKeOM41UcbtB28Inrh0o:avqErNq7pD5PYLsnOUn1DJq7XyUetcDt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.39 KB MD5: f0b4cc1f580430aaacb025e8c2953a13
SHA1: c7f40027b2161305a5fb941a251f23f1cf74dd3d
SHA256: 848c2a5e70796de3f08216687bce351776e957b9190532edd099c79237b36cff
SSDeep: 384:UpZCV0xnlLtZDgnshITP/Kuv+GApfnmiutF7iwYgo:UpZfnFtZ8ska3PYtF7ix
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat 19.95 KB MD5: 8b9cfb2209af3f12eb5826b76f8a088f
SHA1: 522952fd2978d8d89d992901a14ef7adbf30804d
SHA256: 5e0e9193865b0f51ed335ea46d575be5ec82546818288c49e44a8dafefb5d0fd
SSDeep: 384:vWqbKA6W1dh8oeIDi1DD8uWw64YJs0wama0PenTd7z1VjTgmLuWo:vaWPZ2r2VwC0yTpzbG
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.46 KB MD5: 06ed3781ec40182b6adc8451a974aa54
SHA1: d0627783bc12ee61e87c651ab518608bc49082bd
SHA256: e08724674a863ce4b25eff8a9959060f70101fe0c63e7599676995967184351a
SSDeep: 384:QXWwUt2oP6gPIZJsPbeXx1X9r4CIF3+5mo:QXW5PkZ2PbeXftECaMp
False
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.07 MB MD5: 17081d4d5ed97fbeb15d0f61168d320d
SHA1: fb9536ab93cbdc31b0c3d5917b4aee251cedc09f
SHA256: e175000eab0b3250532f46699ea84dd183b0cdff443daa3be792b42331f2a5e4
SSDeep: 24576:bETVtwV4aYMAsvngizo+QPMrwYL7cb4RaNjgzEnw:bETvwGVGzovwNU5gzt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.12 KB MD5: c7ad4fe4d6eae83a92e303f9d7cc6939
SHA1: 94abcd8469478a62923b896d955aa935e58aeee6
SHA256: 480b31155640dacabfea72cdab88331eff32b4e81318110b1d11702bec209026
SSDeep: 384:pDquotA0uLTNDgT0+qt4AhCT5RmQqjHuE2uedZ1Jwnhgf6VWPLLFo:tqztrwTNkY+Ihe1qiueH14mSUPW
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.04 KB MD5: 8ef1c187d8bd56b280b1802fac9140e0
SHA1: 5ef39e084117ed2b8e5e6862e4eaff1c54e1ef12
SHA256: 311bc440d000f7236996422efa0cc0cc6c5aed498ec2bb66a96492b99b8c7923
SSDeep: 192:6yaiomUnJKbaImLEHGgu9ZNCBclv1tCCF82cZkCJuglmNLVyzs90o:6yaYUnCdpGCBcl9FdksLgo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.92 KB MD5: e9efb85c4c467d9b36941ea4b25ac5ec
SHA1: 78cd61c8cb19a153a41b05fa814ac75d7bf30e3a
SHA256: 7c98e4516762c4519d6714d4e25b0a2109cb2e51966b7ee70e42f889ab34430b
SSDeep: 96:cXuve48ElkZT3cyow4Xy8mRD8xXVr8xcDELd71VqoFCaV+2wDQ7wMIVG/r2oXuOM:gk8EM36wQySxXq/zF977t/rUeZCmi0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.23 KB MD5: 01c3f4951c8dccd6e49246f1ce092466
SHA1: 99c913956a45c424da8fc5d21943ed9b8350d27c
SHA256: 4c7e16a1d5c6d069b0b2a6c32baaed0273dfe957c6de6425cd31c45d502ad199
SSDeep: 24:86vHP8dWsn/djpWY1KPXCvakyppzXhnLelmFGr1HjpV8pHkN/Xny3o:7HP8R/YySzlelys1taEpy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.11 KB MD5: 180d06e388cf3f26e8eca180ec14f0d6
SHA1: ee524a26d349c21b0c9a2197dea70d1072445252
SHA256: de2696ed4b0a4d0d5af0de9666e3aa508b4380c02d6a6fec9e644455339bd3d1
SSDeep: 24:hEQyVZKXsFeY3DkGu6xA7C4smZ4skhLxaujWgFWG2q8vvCVXny3o:hEp709egSx2C4ulJxauSg9svCxy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.71 KB MD5: d01970867e705467f67ff216ea82db8f
SHA1: 0004b09d6240fb5833c5ce813c4e21d34e08d74a
SHA256: 0e8b7f4a1f13f058168b96faa5856e8c419c9575c00290b33262397e45d46e30
SSDeep: 48:5/bIb10pgphOjAgLlSRgkAS9OIEQtxy3o:5u0TjAMIgkAYT0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.14 KB MD5: fe43dda3f6f492a6bce7a39eb1a6bddc
SHA1: 9e6b4f1673cdd3dafa29c6c9b39599bc462836aa
SHA256: 990e974879fc1e63648ff8f5c6829220417c5c059bd332ca9c4aec3b0e186b58
SSDeep: 96:XX5aAITa+FiofK3PRy22zjy8SIuAowjcUxTkQp4a1nQcL0o:XgAI2+FieKfRyFjz23Urp4aT0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.90 KB MD5: 746d5dc71a088ea80419db7d547ec7a1
SHA1: ed44a21d29aae5eb1fad15689c339dd81e6cbd04
SHA256: 0f153c918c60bcc8a63500ee3ce728dc2a5d0a67b6279abedae8f9f2b91d6898
SSDeep: 48:5b7U6170waRjdx4zx8AlObZak0L20yPbeYT2xy3o:55d0ZRjmpObsX+T2x0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 9.32 KB MD5: fe527ba90211544267ebe20edd79ed70
SHA1: 8652a7b7640bf81ca5d5a61fb5ac84a786d1a807
SHA256: e06b3db107ea38342a1eca28a621a4f08f9fb97dcc31e00d7d86af6a7cbc4ec0
SSDeep: 192:q9iFL82y2CpqWiQpiRKxqEy3aMI6q6LMmhUFhFkxWcXkxB+SiQK0o:q9Ow2yREWbiN33I6q6LRhUa0xoS3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.12 KB MD5: f0e18d20b5a0bdaa87923c13569e7d58
SHA1: 39f61ecb891b3308bce059f012c74d20af156e16
SHA256: 9a70c29c169acc962acbf369005819e95437f762a339a031479bab92ac878f38
SSDeep: 192:3l+0283aX0MsWzqqqQw1glF+H1QT5hSxHMs5Fog7x0o:p5vMs+Jqb1uCQ9gVogSo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.17 KB MD5: a448f0b5d43c4185edb599a653ef6650
SHA1: 62b484261db52291c0e3352fa6fc0ff1973a1206
SHA256: d3f3db29c24ffcbcf24d72f5c69805544f9ec345ad9eca6b538c0283557e0404
SSDeep: 96:EID2g9JHvqXrJ5BDbtREjUhAEltf4HP7kli5Uby9L2zV4m0o:lBfHvqV5Zbim4v7qiWe2Sm0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.84 KB MD5: cada62ac142cd9f533009c62748d6aa7
SHA1: 67e83c319f48e76b498422d4788872aaf4f16c1e
SHA256: 343a33c3bda35e8a036f5be8abb76b1050bb2358bf1d4f64458f65b80ac94045
SSDeep: 96:v1gdEG6JAcR1+bxqmDb11BJ+9jz2qiy6r7t6/rfDcNpc+a/eFH0ax/s0o:v1gd16NR4lbFf2z2qEWr7cNpLrZxk0o
False
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 373f597bd5cb2981ef587958382bef1e
SHA1: b506c21a8bde021e268709f10a5406cc4a83feed
SHA256: 92ec21436df3291ae78b1d3243e9b9321798a3149c32715aef5641a10b176ce4
SSDeep: 1536:bdbzJfbXw/E/IgRgeacyRS/isoLcGY1gItGAfkZcpvc9x:bjbXw/mIgUcYNs9PttKcpvox
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.75 KB MD5: b7ab669541190fb093e1432f37a7dfd3
SHA1: 33914854f2b5dc37c6f41f4f9cca8192f0799396
SHA256: 64e005f4f8c896154f7324f10f8c0ca45be14a4d117727f52c91dff5e1bd0859
SSDeep: 48:BTaKlmpJAjgV1x+Vi+euExHV5pTxxD864nhLL1tby3o:NJkpKE1xaieE53pVCJnZL1tb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.43 KB MD5: ed1821afb3ea17dd5993a4d6076f29e3
SHA1: b1276ddd005f44be7d6cc8498dc86fba2fab56ac
SHA256: 05e0402f54e3e2e6e4fd3d4f80f0847aabebc9555f9ac18be2ee4ead696fdb33
SSDeep: 192:VSbN8Ym4In5UGzyGxGV+uJIs3sQKxCO4cqpQgZV4oHCDgAjtmpjZqDndJvDMX0o:Ymy+RyGIF6qVV4oiDmFqDndjo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.93 KB MD5: f6e9c71ba1dfbefad47b650f32f7d5fc
SHA1: 520b0dab526f2bef276ef83e4dcabdf78d6f1163
SHA256: 7db6dfdb258df6dd94053be19c30b24d6ced69c60f6419b07ccb5955b7be2156
SSDeep: 48:U4SQLNa2vlGz0nb4r5fpT3zTQJE4sLpNZU0p4sufy3o:Uk9dbMlx3yxoU0pBuf0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.73 KB MD5: 856f8a7347ebaac05d844857eeb92f4d
SHA1: 1b30dbca1283ea7c12716e21ad34377f0ea7dbd5
SHA256: 9b616606eab10bfcf84a1487cc0d384412d17b0f14445ddef035408cf67d0e04
SSDeep: 48:VMoAxF7XeUkU0mYwmSsAWFnbbxkKZtQmb3mVtemejGF8yclM/V210vP3y3o:CoA53mxAQCKrPmfrejm8yuM/V2KvP30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.39 KB MD5: c5026fc896cfe644e4aa76838990170b
SHA1: f4db9f07750be9af30e87650a6290f41a8bf3b32
SHA256: beb9602ebc48928b01e3d6ea7dc9b53ec84743f223ec0cee608cf9c38a12b51a
SSDeep: 96:QpjOJ2wDLp7DpDIXWPKaFBPUsYl7GS8tli4tP8N5qwyFXmbhYdyAEE0o:Qpk2wp726yxsFeQhZmt8j0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.18 KB MD5: 3224c10958fd1f783903cd9a230bc1d9
SHA1: 010d7645b611ad82a6f35f30fa3578e80764f30a
SHA256: 506a894972e47bfb5b2231be3d340639eb1c504ec6dab2cb5ce37e6cafab5514
SSDeep: 96:br2gMXRSw2HbxICL2uC1mzTQ4bQiYSlGBwHpBaX8vAm0o:XZMXRz2LhCwUSlZpMMvF0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.86 KB MD5: bb9a72a7df23173d4357defed1ce9a20
SHA1: caa22d67d0e8e0e572b0b58e823997fa0670b8da
SHA256: 0e03ac0043baf9064c2ef9824a471e5d52c15a74878c0b7ef3c93367ba2fdacc
SSDeep: 96:lQnh1KIkwNfwuTs2EKhupZ/+q7KOzkbM/v+iN4xpazeFY/IBW6B/glkNHwfBegGM:o1JkwRwuHxhe/+sKOAW+i+a6G/eW6Vgl
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.93 KB MD5: e665a4fcdf9f3dc45cc410666c402562
SHA1: e6b11304744f0c4fd8338ba60317eba319751cce
SHA256: efb65934790cb8aaae6c7f42e4907ffdfd14d23d3d84170652bd1ace9eca98f2
SSDeep: 96:+3V9dS/xOQwlUkRAyyoRVEmqxRtaRIlzgA0o:+3/4/x42QAyfVE1sI1z0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 KB MD5: 7be8c210f6d48e3ffde790d821d456ce
SHA1: 403805bcddcde468ae54f0cb97f503abbc4c57bb
SHA256: 3ee2f9be4e61eb4863e81c844a11ba711de987b3315aa32115f320f2098094be
SSDeep: 48:l4Qatdjchp/xrm7fo0/dgWetwdd3dA/9Wt3lo2yNxBtQ1um4+y3o:lHatdsxko0/m5wfaW1uxNxBd+0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.31 KB MD5: fccf6724ebc799c3ad4894aea9058010
SHA1: d74430f1fbf59e816ee531c290b1b60956bb3841
SHA256: d26482c8d90c39bdc80d011cf100247866e7ddec681f8a2dfb4798a34768028f
SSDeep: 96:O4iKqIY7WIntjhHDVdosUFMl2MtUtxR802s5O3FwAvpe0o:OF7VntVBCf9ss5O7E0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.03 KB MD5: f323c3efbde3bf77148dade71a0b935f
SHA1: c18413f74283118325b0a6c92469469697a6d3dd
SHA256: 7acccaa0907bc78d5e8e9fc4aba0fe3000041b6126e2987e3fa531171eee937c
SSDeep: 24:wyqKQ8gCyh6q2Iy17pTMy+w0bodukV6yJwR+b0lCVkzC0T8Xny3o:pe6JIy17ZNj0b2ukj+E0akzhTGy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.07 KB MD5: c635047c32ab6a567e64668e99a3f6a0
SHA1: 5c80dac7c92e3b4286940d553a8269535f91d7c8
SHA256: 14296ef2848cf23910a28fe715901aa3821ede0b27b8ef58293063806420f4a6
SSDeep: 192:ZoO/dkO1eOdJIV7Eju74nwoPM4y9FwFFL0o:tNpdJswaswMyoFF4o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 26.65 KB MD5: f384089e3032317072c7eaa5a5b22303
SHA1: e712e0624a17397411b858be3aff3cb9d8c0b1f6
SHA256: 4b9b8f86087f43c1534b5ff16a3f3378922d2696a2cb7cd040d5bc0112725863
SSDeep: 768:Kd3W+14+q1kfAMwCU6UFjNlgmhaMuLebJVu1xybiskLF:IWg+zFxKebCxybiF
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 13.03 KB MD5: 4d1901cc6aadc394e1b4abeab630a8b5
SHA1: fd40db8d89be86657193530faa3762c068a49590
SHA256: c5b4ec239979c4a150d514b3ee033c593f387534b5491c1d8026b6365f5bc932
SSDeep: 384:M8S6cqeS2rATfxS9TMpkLDOHLxUq9ff5au4o:M8S6MjATfxQM2LDgUqOur
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.46 KB MD5: 8e68c6977f64770c8f0c5c541bd0ee39
SHA1: 143249c5d0ac37a6f33544b0f6496824d4917b0f
SHA256: d7765705e822c121f678b0d3d4566588ea32c1046b21100ce2a948cbe7828b09
SSDeep: 192:ZIFa69ruJI9BYfG6m4I85yEqoNZGoVuMp8hQSdEV6I7x3Ep+3FsV5D0HH6OHZB+8:us698IMG6rr/nVxpQQx6Qa+3F6mfOTkl
False
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 2.82 MB MD5: b605a050cf385133bf3c6743ada30e26
SHA1: 467d14e38997f0cd17a2264b38be5971df57f05c
SHA256: 23dc8b24513962f02d7e94415630123de98b1bf59980c8f3b7b0a7bfe0482e5a
SSDeep: 24576:Y4N9QV/7bTbQW76BueI7QSkYhjQ07SADlOk:FN9QV/X/QT8eI7PkqVSm0k
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.54 KB MD5: 4179e9a67091088755ca844ad273a746
SHA1: 7b653e02363953eea488e672993fa2be1756d0de
SHA256: b4695735772a11cbe79439d2a88a72a9d7683c216e05e509ff359c95b66e0ce3
SSDeep: 96:0708TU0sBUD8L+4wHMvLBxOWrqUz3YTAbrbKVGKK0o:l8TlMX2Mz7OR+Nb3K60o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.34 KB MD5: a8788e054be0452b0386f73385998773
SHA1: e5ee2c580f4eccee1931dbbfa0f797255ec47648
SHA256: 6256745701ba8b02cf707b42599df48b838d45a2fc59694585d41f83588bb667
SSDeep: 384:cGBhuOwS+ohvSRcE8Rpsi4FCs2vBjEQhHjaiJvIko:cau1DohvWcE8TA2vBjdRjz4
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.36 KB MD5: 868062fb49112854dd0f06c025122bc7
SHA1: 98df948ce04a20887326fdee0f678a7478de7d0d
SHA256: 4958be20897db539cbc7fa3cd9a066b2c618ba9e2b9da91c763d222fef3fb656
SSDeep: 192:Qvb7ufEfe79eSywJHsHYnQbVV0F84okAPFWt33OaMEK0o:Qv+H78SywJsHnbVVsok+FWtukRo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 19.26 KB MD5: 4fc177c62c4590ea125c91a24bc376f8
SHA1: bd86258d84560155d68defbed39a4faa9d3d9484
SHA256: 44db61855648a752fd6089b9a64dc51ae2faf3efefaf1344241890a466b9eaf3
SSDeep: 384:SZKuk/TXLW/pyj+Rb+OwfXb3nwotZsKadExcEhjvYH+vzlgo:+Yyxyi6FfOducEh7C+bZ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.92 KB MD5: c87b5f3c68ff7b2ef535fa239d8b299e
SHA1: 770b1042893a67353fe31c1ac6eca6912237118c
SHA256: bedd072e90b11bd49058fa8240e3853d5a54cdf989c17686945fa34e1452268e
SSDeep: 96:XUBYSi9/2HYiq053yMW4hbls3IoVa5JpJ/1Ar/P+/A0o:cU/+Y8C4da3IoVa5XZ1AL30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 27.15 KB MD5: 378e8f5224828cff17dc94ecec8c392f
SHA1: 123bda99d77c75ad11af69a503198b2891a89c0f
SHA256: 52287fe5a37ff00bc8adff331d08434bf6145300d23071d9cde93962648900f8
SSDeep: 768:G2r9HTBRA9CnKpQwIvdBFtx1ps54BiueQG5O5x3B:G2r5Bag7wIT5EQG5O5v
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.54 KB MD5: 473c6e220f5d1f793adc7c08d6841a3a
SHA1: 94c71479f250d9f19bbc222e9cf275120270f94d
SHA256: 5a24d9b974b7b8da9183e5ce8744891111767dc99d9cc76e361f86f979981792
SSDeep: 48:zk3sJDT9GM9Fxfw1+N7HHDHByZ1zTUy3o:csJDRGM9Fi27rByTzTU0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.56 KB MD5: ed05ff096347b145a724d5e272ee1d9e
SHA1: ee8751fb004177972e1a0e8593ff1d3cc2a770b1
SHA256: 6e0a3141421b016c11d8d46afa1e99b607ae989ff6ed20dfcaff2557228cbc01
SSDeep: 768:HROt9CAGjr1iU3vgG/pp4OeVR8bLDmUuMJK9EcyiVO:xw9CA+cDG/TBr3uiD
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.50 KB MD5: f439d395d03a838df4cf1b5f771b666f
SHA1: 58ef8465f024c7a659030c48d68b61d1ab13e3b0
SHA256: 6198e294dd2b57392843770303d2aa434d3aeff7d3ee9c4db92f85c37a523fe3
SSDeep: 96:rI2hc0l7P7DRy+3Z4Q1VMpxMgBOmtMx82BjoBrn0Q:rIz4jDRrJrinBhyW2BA0Q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.03 KB MD5: 8a6b00c70de3b800550ee48e05df5bd7
SHA1: 25f30eafcd8846765a5c467bcd314601d68894df
SHA256: 5cf8bb29c71a48d3b95d10cff433d267dd3eb9bca9bf07d63d286409d267abf3
SSDeep: 192:IdlMaM+2btfyRQnlYhbGh12akzDvT+L5jKiXHMUFg0o:uyNNtfflmZDLS9XHFno
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.56 KB MD5: 23ef4736c11f2019c58f0dd62da566c4
SHA1: 62b52cd3368f29953043b3399d06fb9e041bafed
SHA256: 9fc0eadaaa1eb830f35b4e0910edb3516fc01520bc883d6cbc1d0f86e26bb773
SSDeep: 48:P+3atYZ9227eW1GMY0d5ssAqS7eMrSKWNEQc26a9KThmQGl0VxancPVX2hr5iT4U:G366A9ZgsG5Z6akE0V8cAECglMAxx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.36 KB MD5: 6709df2c2826687b8f91c8ed0c65ce9a
SHA1: bf7bc7334b03d64fc88f5253058e8674fd5293c5
SHA256: 4ec40d87ceadba7d62fcf27a6f8c03f389bbe670b2db165653d61f22bcb4a621
SSDeep: 48:ClOO4c32cfFpfhPt/elCDO2ni8d0cwdtkkO9i1kDM66/M//482/oTJy3o:Cl94c32cjhIVGR7wdtklw10P9//482Ql
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.65 KB MD5: e9aec25dd3bdb82d01bc19dbb7f3a84a
SHA1: 39389a58cf58d7ba44495fdc21da2116de593e81
SHA256: b0eff086b78fe1e434205b1431c2a06beaeee05cd39a1b8a6bcb8f5159d96f8a
SSDeep: 48:cPQQ6vFHOxTuW266qdS/ZnP6RXFr1pvGJmbj7y3o:HQ6vNOR1X6ZSRXFfJj70o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.26 KB MD5: 3c9c3a28964497957e364add87231c4d
SHA1: 98fbab6366ab4dda91ac233751b5a2192320beac
SHA256: 6a8e4602232402600b1bb7d079af727de22f68fc4f0856a17ab074afd6ad949f
SSDeep: 24:Q2kkds4kWv7coxrPBbKR6f0KA3E/NTDQOFwMpLi+UYwMmmUysL1opfSXny3o:2irxraYrA0/ZMDMjUPyc1opf4y3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.92 KB MD5: ba72be501e2393d6034d634dff7907b7
SHA1: 5a28b48f0baef2aeb801ee2bef3b15bece5d2266
SHA256: 8fc1d6be0c9bd5a0ed6eb533f611e874d8abc29e95dd997e0e4e2a3b10e2b11f
SSDeep: 48:Bja72gUvzpD4yuQ8mDyLfTWJGv+5t6qWX3PQVvRdy3o:1gaeL9mDyL6OzqWX3k5d0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.11 KB MD5: e92e4ceeee7d208c20e13d9c574b0901
SHA1: 4522b70b55ca7aa712163527927e1cda6da667ff
SHA256: 22a7fb1d4677441b49620a6e88df6b71ccf5566eaa4fa73e9cbc2f92f7963712
SSDeep: 96:onr0kltYPryqCLLZ6dL8ye132W2CCmmm7aPM/bGlJP2gz7Z90qVeVV2DC90o:4IzLQkN8y232SmjMjiDZSSrDU0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.79 KB MD5: 673d26cc6577defbfbfc2cd71f797492
SHA1: 42865ef4ef6a86e08a7eadede827fbbe730d69af
SHA256: 0fb098c16304bc6aae4773355bd7f14ed1e47afd1202b1bb401ff9ee29202296
SSDeep: 48:/UZBU6bYkhtXVN4ma7e6bJkRnsT5rO/vne66aXyOOBey3o:/D6bphTWbJkRsTE3e33OO00o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.28 KB MD5: c497d6eba6901eb5b93f6370bc64967e
SHA1: 3924cd71cf763b5bb2215d98f2ff8a7853eb1017
SHA256: 591fdb9f3c37cfad6c1c175a6bb141e87d635c6ac36ca1b7aa6ae6b68061b874
SSDeep: 96:O/gqyWTOl8B5PcyRznIo/jSQA1bpsdNN2A90o:O/gqRTX/RzIqjwquO0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.73 KB MD5: d4428e2d978b1368449537abfe2dc17d
SHA1: 7a6543ecd83cebbd2dd41cb146da83661fc6cb01
SHA256: bcc5ae99bb33feb3fef280c0d78a0c8e60e17a8167f8b61207c5d02c239c903f
SSDeep: 384:koWIhNqDdArcu5t/fx4xJz+UZIOmcqkxo:v1ZcurimUZpmB
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.42 KB MD5: 9fd8695f03a78c00c313c49786b42175
SHA1: b7291059bbd3204d963d3399d632e1577f9695d5
SHA256: a352401df4fd304ce4b4ea0988e2547ec77a026dd9081ccf604456da4cff3e2e
SSDeep: 24:x+qRAduzLSmpdijdEA+j4cqc2xoPd4AlSX6hM5jXThyr/Cpfssl8k/5nFzXny3o:x+O1ze6ijZrcqcnBM5nk/CdjFBFzy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.25 KB MD5: d485f8bb622d60a9a58641bf6e3438d8
SHA1: fa4787cdfdd61e7841be261214f226751b478a58
SHA256: 58940fb2d367487dc14735e6b3ce6e88f3c75ec4be619d190659f4140ac2707f
SSDeep: 48:nAuw98JmJzMwuhwT9weYiEgoOUekqdnRcPrAL9rGui5Vsh0IrIy3o:nVUJzXkw+O/kqdn2CUUhrI0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.40 KB MD5: f263c4b7ec29c4bedfc8ca490dcedc7b
SHA1: 470ead4c42cf6c3165202e4500c9560975b7d617
SHA256: 08737d612c4fe315924ad98b64c7c2d8fdbd0732b643271581eb1825afa2ca02
SSDeep: 192:SbkTzRIEXMRNLG0tKnUioEILD44VOgG5kBFAHqRGx0o:OkTCEXMcUioEE44VOgrBSqo+o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.68 KB MD5: c225f3787ede2e923f3223ddd83c7d65
SHA1: 77aae719fc58f61a6ded6a80d1f175bf7cea4dd9
SHA256: 6a1ff1d4d9534956ff97019ff44c3c4dfca71bdda827dd63de9de9bcf9bf54a0
SSDeep: 48:zeYKkQQj2bzhxOofAKqAeeA3DocfdR1Y62Nq4Sb5m3HHZTChrwdLDwceza2iciAB:zGkvQOrhTld2NvStm3Z1dUOciN66hI0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.87 KB MD5: bc48c7524c8149387d112fead8fafaec
SHA1: 8220204a66ddd78b92a58df389cbe90ea4136b1b
SHA256: 3b4601a4826a5975e0144590ab2c01f693924df2dec55fef3c41a900efbbd790
SSDeep: 48:hT0iylNld3rwQMvL+EELg37f2tNbD3vGDWhby3o:F0ioDaQwjz2tNbD3veWhb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.67 KB MD5: 1ebf6a32ff42819e0f71ca4bb7a2a6b3
SHA1: 7f010394bbd01e94df2f841e3cbae795ee8b3c0a
SHA256: 24f574a969a7b1c94ea03b82b9885414d73492b710ad0cef1dc137f6847285e5
SSDeep: 48:nKLkr789h0bT9l1bYCvuHGsoC0jdmErzJPifzm7+eiSF2q+viD9JLcHAy3o:nejvg9UC79t1zJPifSViSz+viD7cHA0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.04 KB MD5: ed8301c0402ea961c7188a5c47342b12
SHA1: af47bb33656e04a54dfca5e9042d5232984d690f
SHA256: 0a0b6f3ac5f49789823d491f0a1a47d431af8533761e63cf7d3e3750f26a2780
SSDeep: 96:Z3YNFKSDNrVIQMMWhhS2HJNqMQjtj1iNtL77d3JLZQ2H0o:JMFKwKrhS2HQj91iN577/LV0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.95 KB MD5: 96137fd94db4526f32a7549ba94f53a4
SHA1: ce591e3ad99a6e4326f57232d2211539c8a84a90
SHA256: 6a9ae8b91bdfae6f17c353e7e34807d80926293ebeeb0324a8397f88cd553a65
SSDeep: 96:tP+Q7oncUpKRAUJb4OvinhwCFkVst7SY0o:t77o/sRAjOWwPE7N0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.62 KB MD5: da00640d4df0e5b7c7c3f4482f0c9f39
SHA1: 7459608ea5eb639c2c11f82d082012d6b84bba8a
SHA256: 0838c924964f6545274121d584ab029c3d2eac5accad2106b3ddf9a339bc3b4d
SSDeep: 48:7I7yPgWRGiA+HErCN+8ote1kx67yy1Dr9b+RQkrIgq6DfneBZy3o:U7rnYACNoXgyg4Hq6LneBZ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.90 KB MD5: a5feaace6b0f555e72732cff6df3b541
SHA1: 916d80a8be1452725717a975c6f121dc3fdd06ca
SHA256: f03772974796062ec65039b9804ac97a8bd201b4c6a861b864f47cc85c7a7abf
SSDeep: 48:98uCE5Hlq7GN2f9I0XmkAJ+BLTZWWNSjWKZAro9O0Y1c3yA0OTQVPc8AWy3o:euCaTN2qYRA+NsWYso9zF0O8VLAW0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.65 KB MD5: b16e893b9e173741220d8cdf40829a9e
SHA1: b46eac45bb262fc68edd2e82bc93b0d0c978d956
SHA256: 272b2a2835ae8a48804a2d917dc7facc9f62986d5ce4c7521af5f1bc0b6df15e
SSDeep: 96:B6iAsGntz7fZ/FaAWBWH0hpd3jOc0LctE9DKVm0o:wiADnf3c/tKP0o
False
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.35 KB MD5: bf7e41687167e86c7d386623f2581d72
SHA1: 43df2748621d9cec9e3dcd77f632e517c21cf527
SHA256: 45aae071890cacb10ef6c7a91939b3895e475af65d592d32e8527956939ec849
SSDeep: 1536:X6Kd5pkN6a6zlchiJ9eRailcy4sFtc2QzMNzZlbrvj33pmsJG/d:XFkR6zlchaS+sFK2/JZRjHBG/d
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.25 KB MD5: 0254725ed201399db6836337a91b379e
SHA1: b9bbb810c97fa15828c019ae186b603441e37ecf
SHA256: 3f827a8a36d84b0b40c525c58c9e830feee3e7671f0466bad9108a16bb12849d
SSDeep: 192:K1Xf2p/x0XXNnwhm004k7VNz5lS+RMad2ACjaEaSYhb0o:K1Op/x2qq4k7VUK4ACjtXo
False
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 4d8edb0d05ac3962362f44cd6a6ce656
SHA1: e64f5878ca1c0f43176fac8de11cb824c056ef56
SHA256: 082dd45a2dad67af24de25c3a5657b59ffb7fd92887ef1e3edd8c3f3b79f1044
SSDeep: 1536:UiusVvw7CLnQJwjW52j5bQWoamoWj5rM5/IPhtocQDkc3EQy1I2:Ui078Uwj4OooP5/IJScQDkcnu
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.89 KB MD5: 1d5ad2c61e769c4ddefd6e00baaedfa5
SHA1: ea8cddc9f8e0a3ee53e16ed7b5c422ee61d43119
SHA256: 79dd6347cc8dc1b927a319951fb0cfa79a461c0fa6addbe4d0ffb8de63ef0015
SSDeep: 384:9AmybqkdqHLtjB9OTiilX335FAmLrjWTmdypeM+sEH/o:9ATqrVOTiM3JFXSJpepsEQ
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.07 KB MD5: 1de2983f6e6a1945fde071e53fb6efc5
SHA1: ff54b7b6d9868d99f80a205bc700f0d1312e2648
SHA256: f59accfe94b24519a0687ff89cace5114b54a390014a171bacd995fb926fed7b
SSDeep: 48:7Wn1Vzz9n77xlW2wrUXy6APahH+bPJEpPQTsubaT/+y3o:61BzRArUXSA+bPGeTsCaT20o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.53 KB MD5: 9d346c49f4775f1447222216dd34e0d3
SHA1: 790b7e5b532c8b632e625cba8c0bd7a3e38747d5
SHA256: 34b4e167a4186a24448940ab37af2d3a33e42c0151d8329b2a858a1d458164b8
SSDeep: 192:nEjpqakKK5pW49vrddVQafW6q5g+RHPLODqQXrtLicyjY+zRzA0o:Ejpqh5pW49v5dyYWNNRqDqQXpM8+RHo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.09 KB MD5: 03d465a9aa75c16180cf423d5059f866
SHA1: 554c3e88fcd8260efb55015a367def1194a8487e
SHA256: cc409d8689f45322fd852262fc17aaae7791bf76088032129a46d473440f4c7b
SSDeep: 96:89fely9EcRqVqRjQcUvgDhDtXzk1Rny5uG2tcUFT0o:K9xqVYU4Ka250o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.71 KB MD5: 9669892146782d0eebc63c0a9d998246
SHA1: d262984e6a58c94bfa54a57da44378a143c3d96a
SHA256: 6ba318030644820fe5288874902e9d54027d37a2da29e9c1adb1a796ab20685c
SSDeep: 48:0Xtc9JKVhfpkXNSTvhIKna8fFDOLLmqM/5HZ4RVhqIo6H+mm5c98QSfm6iPwdclF:0XixXNSTv3NKOR5UcIdH+je8QBqd2B08
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.37 KB MD5: eaef9bd76bbc408fa7a364b0fe8b7145
SHA1: b26c6d96774d4d5cbd27e49ae51e541a41b39198
SHA256: acaa2ad8221fa3e1802ae028fbcd1b655a8eb160d43bad4638219045bb4998b4
SSDeep: 96:WeF8PImhcAA/K5DOw3FiLMdSgUT1QB5mwaVUhOsoy4xToU0o:WeIh1AC45wE73VUAFx30o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.61 KB MD5: 31dc6b5a0152ed8fe2fbc7303579038c
SHA1: f2f03f53b9a09a21c54a20d278feab66d580a796
SHA256: 7d47bbb35be9bbee88440f4af1aafe7c5ea9f1e2f7eb011493c3b6cae36dee49
SSDeep: 48:1FVChAMqm5xp8HYppMZBFQkfNdgo+TffKGcXDGWwmWrjuf3BL4whMy3o:5S757dmRr1dgo+TqRSmLaeM0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 5.38 KB MD5: 26e19734540e50ea45ffca081b1a1758
SHA1: 79c6335ea9c44940cf2c135dc28925b83db58afc
SHA256: 69e93bb4b5afa671c93a723a522aa033bb1b809a1dc7e54838c97b7e13dbb5a3
SSDeep: 96:S4ly1Oe9k8ogCqpCyxXxvrI2DkIbYRy+WT73e05nwJwxKF90ml:mHG8NCqpCyVxvrIgkIbY8+Kh5wt0S
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 48.62 KB MD5: 7ad59bb08aca29dc5e239cbf925e8791
SHA1: 3147bb004d386d895bd1851085caa30f1bde7be5
SHA256: 01cb525f3be1421e49af62f9d40561c7a587c2e2b54660fce37ed2ba0d86052f
SSDeep: 768:0cV0nPGHoqnNT8tGZWoJWnYrIPWdkZRQbloUr3YJtDOv+y212qSqeYJ7Kw:f6uIq9+YrIfS5O/8zqeYJ+w
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.13 KB MD5: c1ccd2f08811e1e1af3e096b624a68cc
SHA1: a5b7ba0fa04d93884ca6e1b1696543f238c1f17a
SHA256: 8cee54ca3653e05948260278b6bd6c3426c83421cddb5592a8b12f70f922cd0a
SSDeep: 96:9gw8MGWDjb3Ck4NDXF4IjjA99v5PtBrkMArm0m:WKjP3MJ4UjgjtxkMR0m
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.32 KB MD5: e46921c99c03f6d17255eaeba15756be
SHA1: e729875d8509619414ee7244546b24520d7bd9fe
SHA256: 22d06ddc69c0922ef9c3c9f763f5b87ed5b510e21c2336683a9534ba31105a88
SSDeep: 192:2Fwp6JA4KMbw0D0uKb/2ytWjEqHr8o0bQAgfV7w1/u6ncY7jeAYiD0+:2QDGAuA/2Hjwjgfa1/u61Dg+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.45 KB MD5: 3f51f7aecec6595c4bf4f462e88534d9
SHA1: 5414f6af68e3b587222b2db0d5cda0eb3fab713e
SHA256: 5d210dffa6dfb0cc0620e8170f24e48a3e26d3c40b4b44f194cf9e6055be7248
SSDeep: 48:9RyMq37m643houfXh09gqpGBHaFiYn0WpPj3Ayg/s5H4TKzTgXey3o:9J8SF/K9g8GBmf0iPD2DTw4e0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.44 KB MD5: 22fd4697b86b958af5d0030a97e2f4c7
SHA1: 1ed1367c71af813c22287a8932dd7d527f1b7357
SHA256: a61e116d7c4ca2ca8dd80a62fece64705b61a74d544b7495c9bafe7b81b6be62
SSDeep: 48:yGJlGj5MJBEMUaQY/tmAF7PraTqak98RuPtnYb3vBMQqBVaoPO0xaFw7y3Q:yxUfUxYLprqqHr1ncMpTd2MEq0Q
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.31 KB MD5: 0f63e232105c56bee7769e0493257f24
SHA1: 4e83587640aba0e34058a92ea3e48c2c74124fa1
SHA256: 1601953cf065fc3270d0d86847f8baef1f9b7cc47138894323fdbd1f393ca783
SSDeep: 192:iUPBH8m7dIeL95thrjGKJagw+HU/sKUmyEpHjp/VTte0o:tPh8m7dIeLTrjGKYgdc7zxpHjdlo
False
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 7147d7d0cecc38134f6c43875a116810
SHA1: 87820125ac9814d64e886240c9ffe0fd3b67c5c6
SHA256: af033f6f1887161245e74d9a43282fedb05222e4aa69ca764989f4f553e63618
SSDeep: 1536:1lo9RAUSjmQNM2q5uH5Qj5ULmfZZkG5nSYXeIjTQGXZ9LP:cR1xQNzqaQyLwPkNYuIVXP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.01 KB MD5: 0ddcc59e4a03d39639b3c0dba8842744
SHA1: 8a54276886bc565831d81240fd84df790901ac7a
SHA256: cdbc247a7ded12802444b05385ae141ad53fcb4049003ba5ab5a5420d802822d
SSDeep: 96:VSxCPqOib9sk1hsohezRaodnKj7z6NHVTt0o:VSxNs4/hegO1BVJ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.87 KB MD5: 159ef4e0c4b6db58ff8a5c0fcf2062be
SHA1: 0e55692bfa885ca43a756a5ac3e2df97a85b42e5
SHA256: e92030df909e23db9ef13a8e1c39bc24e30764871933b8560bfc37deb28c5c44
SSDeep: 48:5uNEJmNOC2TpzDTE6O+Fj62bmBOdFvlXA1zW2TCDK3bO/YBhcO9NOAWUZTLmnFZJ:Bmn+Nn1dxiQdj+7TCDKO/ClT5WwLmFRt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 29.17 KB MD5: 6526110ac4c49d20da4a36a436889805
SHA1: a7233e8a614cb931539265116745e6e5cc881dfd
SHA256: 45a4efa115015c29d873b109bb48a566645694797b827ff5ffdbd6263e2619e1
SSDeep: 384:DVQ1MpdotMgDcJqWdNorJL2AExN1ldAPkVpWpXkay8zUUiVeapzWymQPl0VMG5JT:+1MgMJ0VvqN1ld2Tkjghin9mSo5tYQV
False
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 44768500fbf2e8aa30c9d80d2e891e97
SHA1: 62a32d57c812a2a891ee5b2da10388275c8bb368
SHA256: 1cdeb16113eda4fc1a72444bd1833ee88d3d2da98e0c5c92e3e434a24ef21a6a
SSDeep: 1536:rMLFDCVAPFwhTG1BUgKMvvV1FQqFq1M2FVkCNM6rRaxASgOk:r8OmFwx8KgKgtFq1NLZM6dkA/Ok
False
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 224f43ca3fdc4bc5e3265c7ebc1e8698
SHA1: 8516d64b5cf044d0eea2f431f65178863715abb3
SHA256: fef5db19729e1ef1433de559fe9ea27a6d5e9fe77ea058d1ac3d041257de16bb
SSDeep: 1536:aZJRbJFCCCbWV7WoTI5gjOwAZSEbtdXu3PwLxN5FxJFriakTs0rmcP6HHon:4bJFCCuqatbtdXu3oLr5FxLrzk4ymcPP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 37.32 KB MD5: f708795a4c26b35b4a2f3d838cc2c963
SHA1: e9e4c27662b30ee31f9805d32d98e1fd9f084af4
SHA256: 9eb1098dd80952d4353a09bb8efbc35c2e42a4de7e6ac45d18f4136ce4280082
SSDeep: 768:4/osEjCZv/TG81at0e5kFQQ4URbOza/rg3t9DHfuuAvRylDO58h+rc:4Jv/KRt0gkFQQTga/i3Apok8n
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 39.32 KB MD5: 52e3da590b83ff80143b01dfc34b9cea
SHA1: bb79585c50b35cf74f045ec487313c96f4843ba2
SHA256: 117969adc830d0a61b933e50d7a3082cb6fd29b5f46c6aad91c0a579f06dda98
SSDeep: 768:bc8QqfH/K5xfIwzA3AAET1Kw6Mna8QBGM3Kr429v5:bc9qf/Pw0QAET1Z9bQBVe5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.42 KB MD5: 34a1c7d49ef7c5bd610a48fe549b89c6
SHA1: a94327133b636a62127249c911eb21364f7c0611
SHA256: ab41f2c8bd2288a50013a977e5eda8ad63253618a98a713dcc03cbf3ff55a359
SSDeep: 384:LK6ckO4IUb1TBCBjPp2d3SF+smzspekXfal315fRAgq19w/KNio:h3O4HhNCxAzsAkyl33fRsmm
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 42.14 KB MD5: 5c8c545c72d21fb8d5dce01e4d114b8b
SHA1: 28ba2ab6055684c1ea7b95c69a4abeff718b11f1
SHA256: d15d91b79344c980765c76cef23052f2dc17c5ce87535eab2649f6975ccf2cb0
SSDeep: 768:iezlZaJnL1Rs+LiGxKntmRZ38mH6CeJBYD+t9GSzCbKmz/hvCoJE5:FZZqnL1RsCiJnA/iej5bK8/5BJE5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 956 bytes MD5: eb17b7e57293cdf7f3dc2bc55e704b9e
SHA1: b296ed5e9ede4ebd1f54ed349420b2fd901262f0
SHA256: 84e691476ab08ba4c6361f083aab56dab84d53f0e64b3e935c80ee204c36b8f9
SSDeep: 24:1CaW5ZeTuaC+98FuMZFbSKJtIIRTfWIKL6y2Y8qfXny3o:1ibeE+KAutX9AgY8Iy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 42.23 KB MD5: 057c6bd5442738d8d3838c2f6fb4d3e9
SHA1: 460e21ce81ed20787d43ac46c37fab597d3b12d5
SHA256: 33372702786cad113a310dd403bd7d0cfb81e51e8d36af3c879d9dadaaf89e7c
SSDeep: 768:feZj6ERFA4B9HT877KyUM7WF9hy+Vin6TH86ZYPlKrXzCve4tSvLMZJKpjYQWaGU:fsj33A4zHYNUhhpEmH86ZYkrXuve4tSf
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.89 KB MD5: 19a5011a3ddfb217899d0fc33f68bc96
SHA1: b7dcd0d4c6ae8731d2dd21d6601ba870e46ab08e
SHA256: b225e00054d5a5afd4e210f84d95fd9e601c074255f93f4a9644f5ac681127bc
SSDeep: 192:jvF6aFGBOQPfn/zYuJELoa5AyGGn+3m0en1DtLJxM0o:jN5iX/Euq5Ayx+GnNlJNo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.12 KB MD5: a35887ca45db3e6022e209b55ce05d14
SHA1: 1ce925ecad3551793314202d9bb1e18d1b4c4001
SHA256: 8dc37503b3759bb0350c17d873b9512ecdf33e81b25c6627e5790690ea1a5d7b
SSDeep: 96:0mdYdpXdYR6aIFQZTc29cln8zEpaiymuh/sjNpH5W0o:0mdYjXuRJD76ln8zEdkh/szE0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 10.00 KB MD5: 4bf4044afd5e0035e883c9446dab427b
SHA1: 4da5f0778e3d15370b32c9a7ac83fa0afa575a11
SHA256: 620ac3b1267ab5e5fe69708be14f7634f70974cb2eea644e34957408e161567b
SSDeep: 192:8e/nKDPELNLLvqrMgnqlHxqpayj6Y3y3ugMb7tjicoIhiartienbe0o:8ecPEx/vqT7mY3yegMbhjiYigi0Jo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 20.54 KB MD5: e5366127be286c9007694d75b42e49d3
SHA1: f4a2b419626a6d8fc9fbe4501d4244cba3b44e62
SHA256: d555345265eeffa318c63f193cd5797e736522492ba7686a1d957c70b5ab1ed2
SSDeep: 384:ElyGaQZ6SYj+VFREG3g/OGylB7VjsxYFJH3ZZWtYodOyhcNnOkfO40o:oyGaG6SYj2FRVCOGiB7dUYzjFodpmv
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 24.25 KB MD5: 93ff78bf5a5050760bb1dd1a04529b36
SHA1: c7bce3ce8da75a4a920d407e89d8b0ec80bef05e
SHA256: cc59291ac8005a1135bc38cdde0141f644936e2afe242935447cc24915abc8fb
SSDeep: 384:AgmISqEbbp0QBA1fFZam8LDFR6RsBdoYS5nRKylpVunWp1lGBGJN9tTCIjxLZpwS:OFvppBAV18lR6eBdoYS5sjIjxdpP
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 248d21c45582c30229c8393e9ac7c258
SHA1: 1610b25ec4625450ed7f7762fe39bc41843a658c
SHA256: 2ef65d267e0ad03c7c1e07ef4142a35527df6b6a6afd5faa34e0118be31beb62
SSDeep: 48:jsIZ4gQk/RASzPmChoYAP7yCMSWkxLo34HZXA7j2VLrh47QEy0dy3o:fZ4gQk/jmCRA7WkxLooHZO17Qz0d0o
False
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: e7400931a6ba08c16a877b84c163b381
SHA1: 370d348ac54ee2b79bc3d0fd47cd03d537c24b40
SHA256: 6a1c3a3b9ed792bef45804eb14cdcaa7bd83a64ee37663191e60803e33c9a052
SSDeep: 1536:cD+9lIiVhaDgRWCUoPfUtKVfdn/99Q093F0YnXMi5i2DF6ZCHZ:y+9lV4D+DBnUt8Vx910YXMiQPw5
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.84 KB MD5: 9f6534854b4b67d12158429d276460a3
SHA1: 7f1f8fccd28b69f6d70ca5818636142050f5bdd5
SHA256: a1988cc3615489244ffc2c686c184b5dd2995a7827c04991b30ef9a226e6c588
SSDeep: 96:HXnWVXuN9c3SzDEQWC9GnwH/jyZ9nHsIsklbmwb0o:3ZN9cQE3C9XqnHtplLb0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 14.71 KB MD5: 0f005eea01fafbfe899c9751da6d4056
SHA1: a1dafe647dafca111a67cc589751204e5eb36b6a
SHA256: b8cd02b269a2cf78be3eeff66b51e591ce62fcd1f83ce37cbd0d57d168924b0c
SSDeep: 384:HV0cyu4gtkWOREIh8QF5a5iQMu2H6jal/ATXdClo:Ccldz0Exs5qiQJ2H6k/ARX
False
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: b4d76f37f07e03515f767f2e6ff05090
SHA1: cb189d04238de887a822b7e8986719f8dbea95a4
SHA256: 9c970f1ad88be3ed80085cb5bea88628de44144e86ef35848bb683604dd30578
SSDeep: 1536:vbhm2px0NoMW7QmIgnKzFnGr29gCorS0BEvW8z6rBMA45:jbdMW7ognKzNG0gCorS0BEe8zcMA45
False
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: ddb7af877d44228eabf34a52275ffbe0
SHA1: 314e1781fb503088f16477f889331bb36c076915
SHA256: 5c47a77d4ca4ae56f20dd664375bc46269f6551b27e2521fedf112f4f8d8a70a
SSDeep: 1536:lAS39Gsm/cN3IKo0+2dV3D7I4lFWFkX0RLUQTq1Nw/:+S39PYcuh0DT7vPWS051Tqjw/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.78 KB MD5: c90ede24cc6423a7f505e1d236669321
SHA1: 7188f57514dbf72c2ad7ec4ca0950ce63bd0c4fe
SHA256: 08d455d609575611861f5c58449b77281336deb1ee4a864dbfebf64431baff76
SSDeep: 48:rWRMK/Or8XtfLh39jtfhwYF1oTZo+pJIXJrBxLhKcfzMiQxZCinrzywkn8H/B/A9:CGKWO9h3lc61opStKsiZCirPq8fJA10o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.32 KB MD5: 8619538b04b47a5486166ce4693a99f0
SHA1: 036423e21dacc76334410f52d52478f239002233
SHA256: 682fd1adc7b786f5983e24c135e5c693889fb8834729ea6bebe9553ed97d909f
SSDeep: 48:4cYcCC9iZd3Yk0i3uUMDN2Z7VCiYutdtoipLKb8nUi+rh1SqOmy3o:HYcClZxY3i3uUo2x7X2QLLI6qOm0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.95 KB MD5: 4558fb594b8f844af726074c9ab710b4
SHA1: 63ef5cc99f40c72c918e53796e8bb9dd866a4302
SHA256: eb85fb9ef72baedc2b42d7e50e751ec303efab56481e1c6eb7faa6ab97953bf3
SSDeep: 48:/bsbjPbml66tGkQH7WzTZ8i43AK713o6LGG5/3x/Y6GWJ850sJFbOMGgTW2qVkav:8bmI6tGkpBu13oiT5/VY67OJEMG8WBkq
False
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 1.00 MB MD5: cbeab9daa958bfc7847a95a294478a81
SHA1: 7b2aee0653a0518060eaa619867391c6e1b24999
SHA256: 93ad9ece12588585bb54676284d856f86548b042462ca47067bb85b74aa53a49
SSDeep: 24576:y5XnZmGhl9iQIwmagd2iYgrEnT++6Myz9la+7yL8Vps+:y5XEgiQIwmatiY+ST+Rla+OQzs+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.96 KB MD5: 8eb8dc75b5113562b141bbcba219e5ca
SHA1: f7fbfccf979798cce68260b46bf1bfd02d54f2cb
SHA256: b7366b6954ed1f8ec8e04f64f0387892df620944e56a12418403477d8332af25
SSDeep: 48:rSTLyqqOtTECwvoimLXPF6wla9mrfcix/XJ6vqWlganwLbep/RQDEBc/+W/muQoe:eTLvpTECwAxt6Z9sfcM56qWymp/RNWmt
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 30.64 KB MD5: 142aa757739c886599dff7a6f87ded0f
SHA1: 0849ab923aeb11b76ad202400e8062ca61339fa1
SHA256: 12f2e3506e8d9d1500e621999abc7a5043f4445ef6a8731a16e22c375f143808
SSDeep: 768:9JuPl6KUWrOv1UW4Cxlxd6hsg7au+n/1k0m+Me:X0ZUWrOv8Od6Swd+dkHo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.14 KB MD5: 359cb8169d70ae0145372dc7528facee
SHA1: a8d425ee5d744e141eae5f3b1c71041020e2d2e2
SHA256: 0de4ac02ddd1ba10abc1ad8af6c8cabc04edce008a9e1fc0ef64d3f8722de321
SSDeep: 48:VU425IWlxqw4vgU400kOLB614WQsR5ex8JAiNL1gggTWw6VpH+Uj0BDYIy3o:VbCPKJZOLB9sR5LmWPTSBZ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.75 KB MD5: f5fa5d5de2349b4fe39932bcc39cff0e
SHA1: e3f8d763fff974857e47fe670c98634cb09535f3
SHA256: aada06ee45ea376518e8b37be4af54b2cba27a536822ed2403142133ead1b382
SSDeep: 48:JZICAW8Kvej+jPbGDoPdfrE62SOKm46x0TyEb86Fy6egJy3UICSKi69sIRS69GX8:JZyweCjPy2BEQ6eTxHfNsI0qGOzfX0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.14 KB MD5: c6492ae532535a0283559c30e143f4da
SHA1: d89369bb6a9f5c725fd3fbf7f55d57087e7b2416
SHA256: 5e45958cfe85fec4100b4188baf64f8d670cec754621b199329ac9d09797d13f
SSDeep: 48:i1pGpK5qNLR9S2GXhMe095mgYuDCkfaHy26JG2YVKhUaL/K64t8C1aEDdy3o:4stuPhZcmgmkHMuUaJ4qC1aEx0o
False
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 01fe382ce342626bf617dd0e3966ec05
SHA1: f5178d5dbea12fd3b689ce740fac210957672b22
SHA256: 0697e76fbdb5455563dde67b73d4279e19b5f16b85816d5b10aa3bacb8b171d5
SSDeep: 1536:PgqxIbQl0S++ax3vppusnIKgZpFaiFtYOGO2y44luAVNtj90n:PVeXi7aIv/tb5cAVrj9S
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: adaefa4e21e3260fdde01d603f8bbb41
SHA1: 89017253bedf32e3c3109ed2bb1be007cbc403da
SHA256: bc2712a80f779d4f46098b62562f4a813aa26c2f6241fe9a39ad5e40bd24fc0e
SSDeep: 48:lxDly6SMjtqTI7qC7vLCznuXvuQ/pnW8oqPu2ZkXba+B+cmA4htIQhfAly3o:lx46SM3qC7G62evu2ZQG2f74xtAl0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: f3d12a16fe2570c94205738841ee487a
SHA1: cd0cdba4c2b3ce06dcada5962849f447b3c1e957
SHA256: 7fb677680be333ccbb96a734bc5b18ac221a8f756ce2413ff1c6f3c14b8db170
SSDeep: 48:oNhLX63bP6n1NTqSh76ZK/cePcAY8qLGbGBjGpnxt7Mdh7/cCy3o:o+3bP61kE5TP5G0j9oh7/cC0o
False
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: d7762b926022ac7c4953fccc40116de8
SHA1: c70907cbf760f79eb254c6ab815a4e92b9cf2775
SHA256: 7b7e0d946836ff5c87b8060142b3e9dcb0f61c8922af5291a0b13d9b3f1e010b
SSDeep: 1536:g5kzGpLEmIaSIxz3yW+MktSLzrM57sMZULgYfBYmP7VTcdha:Ekzcfxz3yFMour47sMeJZYmVAdg
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: cc57e50e90b2b041454b402fc52c5fff
SHA1: 13f9cc16e16d2b69122094192d738f967ab32b71
SHA256: bb3ab1dd948bd9ee52fc42d2085fadac7b3d0a3333b5053a28bd3441f5c53c9f
SSDeep: 48:aQmDiR1nnTieHgbLl5gy2vxamuGILJ4AgyYMhIfb2utMT7QTxy3o:aQmDK1nTiZfIvxamuGgJ4CNob2SJTx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.12 KB MD5: d53a6a8167c84bd830aeaa8e2f1751ac
SHA1: ab89682e4f2d0a127147b5d80915df857a04651f
SHA256: 2b0f572da63cac0c0303323d2a764d8bd0a737acbbac75943edd0f4028ed9e36
SSDeep: 48:V0u99TQ8RqC187a+Qp1lCKE0LvS8O5my0lYdp1jtknG4tSapy3o:CuvTQJC18+++nbE0PTy4eunG4hp0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: 7e1f1d7569c2337d8c8f405d6d822249
SHA1: 8814799505abb0fcdcc4840f9e2fe0dfced38324
SHA256: 8e1126f109c975b07ce2fe5e47fb407a2c5ce52217561666d7201b02efbc2fc6
SSDeep: 48:HQfgx3kxiWa4Qpt71anpM0n94auSluGDIPz7ynnTFTEeaPmrQX5AQy3o:HQYhkxKD8pM06a7sz+nTEPmo5AQ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.20 KB MD5: 4a5ba913a45b20a930402d198cbe3a99
SHA1: 15dd4943504e5ff290112d48e83bb29e102566a3
SHA256: 6f2b84fd2b8ce29c497269070c52553c2df9d1930522ac326a909e59808741b1
SSDeep: 48:3acO9AVBPkcZ81QnfbrUfpL74dAwuZW0k6KbGxPf3A9y3o:3axuZZ8qfbrcL8rWlRKK/A90o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: 256b96ff84a89517d632c7123eb2acef
SHA1: cc934f19147c5b1e746ff898480693f730d4a578
SHA256: 32a097c7e68193863fb1348daad7f0f01ac53c5ad0c1dbbf83e569c6977ee53f
SSDeep: 48:A+UJH4M2eD6OM0jPufxhujJpUy4IyjzkoXI4QZbdnRTfmZKy3o:hUqrejrjPQxhazukoXI4QxdnJmQ0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.59 KB MD5: 432eaa9b842f2055f9be421ace612e20
SHA1: 6da66797a41f5f515f4767f55559442c6646195b
SHA256: dfcbfda25643ed879d2f186400015442fef0142999ef9a91678050d1186f0d6a
SSDeep: 48:7vbwmpE34s+cIa7SY+tG1uW6ofXdU6UrGsu1fec2BBYTdFEU8LpXJmAqy3o:7TfpE3+XKf+tMua1vU6ncBYTzEU8LZ4R
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.25 KB MD5: 5fcc67e8066d3619e0760a54cf9db1e1
SHA1: f916702a6c32874cecc2ec6cd327f46d5f04ab9c
SHA256: 0d0a08563c89df4776d9fef5f04188a31ba714f57f3cc13927ad46bb7432ec91
SSDeep: 48:r8iZcunnQkYu7LBVeZ43tgSaG5Jmg07TdEe/nWd0ydVeBBy3o:QiHnnQkl6Z49SGL07BEefWdSBB0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.79 KB MD5: 1d370c2584d90cc082e5fb9c48bd023b
SHA1: 06819731714c3606d8321977bbf9b7964bf96e55
SHA256: d93a809b95d1055aa7bef580881bdf9fd3d2bf6d47ab5c50184e8128bfe66fd2
SSDeep: 96:4fPzq43q1ratJESxhTtbUNtn99rew9U8wTBKW15ZcM3s0o:wPV61ratJB0nPqew5Zls0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.42 KB MD5: 307e7132bffe94382c953012d3f63b28
SHA1: b97c500406507f6958de96437a23cda4c358aa0f
SHA256: 312861dd7b785382bd9423e6eb9078f3a4c83931160175f2b09c5097d23b70c9
SSDeep: 48:MtY81ods6comZpCFXhFw2zdLoxu4aCytiPBGIb4cG+8vlP83Zxy3o:pGXjp604LlChGIb4fZlk3Zx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.00 KB MD5: 764352caadf8ddf44c1ab2b8ee646753
SHA1: aa72b374fe428ffe5f9b00d2357587aa018f6def
SHA256: 0625e72269b003facfc6206eb4414e1cfcfa6e0db65eb1d00f34e36045ad04c6
SSDeep: 48:sBv4fdAtTBB38V+ANP+Tc6JPijmgVHtHYSj700Nuy3o:cv4l0L4sc6Rfg+0Nu0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.09 KB MD5: e1a1f9b90fbe1b8c02477d571d251fe9
SHA1: 9705844db844d33aaef25df3efee33da7a5ef32e
SHA256: fa0d263b2fa5f7497baa3b4dc406b372f54390e6077b08176094abcf9027503f
SSDeep: 48:N+QmcmgkfSSpsXu1aq+w04VxrO9j5mKuoSTprfy3o:NbmjL2Xq+IVQEmSTx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.95 KB MD5: d15dededdcdf92141d118088b0c3d035
SHA1: be52b4c282451417c13975fac756e6f7b3f932a5
SHA256: 04e043c0e2e631aaf9d78670d15c3f88dfcfe4beb610a8bcdaa1a00f38defc0c
SSDeep: 96:pfDCx7usJGqITx85v+vJ/b2SbUXS2eV5HoFmgApd/gc5gJHRCqv4LKX50o:dDCJVGLTx85mL52e/IF2d/gMg2w0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.65 KB MD5: 0d15b2debdba400fa96ecc978cee9c70
SHA1: ce93c481179fc5abc387d33561c838289f63ee0a
SHA256: 3f9fa72702a579faf69f27f20b0534372e73c5f8a01837408a4ba3d9e8ebb283
SSDeep: 48:yme6dDDJfNWkvnA9rdBxL8QSFRODKDy7k+vty3o:xeSfNWkvnArdBxL89FR3+7k+vt0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.17 KB MD5: 6f9bcdc869fa9befe01fbc55a97eb126
SHA1: 06fb692f3b9d26e1bce749cce41518de6b26c3a3
SHA256: e4eca2479a9898d9f9160a561852ad7e564bfaa76ac2e375ffca93492755bfa8
SSDeep: 48:00KWpIYkgDtkEmhpzdYR24laBcmNF72YeGG3wr1OoBcr8T6XrK6KhVuOt/PLGxy4:0eIoaEmc24lkrJGAwSSXrgyO9Ts0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.21 KB MD5: bc48a13ebb7cde8a0d730cb413cd91dc
SHA1: c2e919914ad8cb6d74955d9caf01bfd90c6790c6
SHA256: ffb29e744cde556c494b1e8738dbf0ea74ef0184cb2c465410f3cf1092c4c7a8
SSDeep: 48:8bVJfVjxth94MTkSNXBRwIoVnNLFSL4NRWzk6gec9oriksEy3o:8Jt7tvpdNXoIoVaLAWxgec9o+E0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01183_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: 1a0b4b24b259f87995eb9e91efd12c42
SHA1: a25aeaca94da64fb8061b35fd032102b4f9f2348
SHA256: f1c5e3d3855b65082f97f04ee3055182b5a3dec6f6065b5a8ceadf1e91bce83b
SSDeep: 48:thHb+ExNiszwixjGqBhjj5qGUi1/9q9Tt4h7g9IP8kDEszxZQL95fDv4txy3o:7b+ETi6hjG8hjj5qdiyRt4wI0kQLXfDA
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.61 KB MD5: a7006253c9b4df26a74a06ed1ba1dc21
SHA1: 68c6d1b6dca3cdc5678cd6c9ad066ac4045c49f5
SHA256: 49d30921ebae79778fe1edf80319832b39f2e2af2bc959916762e94b7a925273
SSDeep: 192:dWmrmaOibv8mGx7mYMjc/Hjs868tYYeSrjQb0o:dxCiAmRYMjSO6lpjQoo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01366_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.96 KB MD5: 8d3786903616d259417443e370f27da1
SHA1: 6f3bea4137ab3db510209457c58873368b70e312
SHA256: aa912008664c988005b9f623d307747a127f2192444ce260d416675a43bbb219
SSDeep: 48:2erJ07odkygi5TVL8ovGF7tEXCv5+2EqITIqy3o:3Rdkg5BL8ouEk+2zITIq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: 104f33bf12235b4ba18aa8a953a89f68
SHA1: 523c233dae94aa5ccb7d1908d6a73d6fd47cbe2f
SHA256: 3534c1579ced180612da3eb2612fc3f888d40d6cb6ba92074fc04f3eef55ba58
SSDeep: 48:s0B3KcKJP735TLEPj4AUk/v8mV6OzDLbGNRTm54Le5R9Wl3pbhuRKitzCxy3o:jMhdO4y/vwiPERTm54V3OXzCx0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01585_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.70 KB MD5: 1ddfb85ebb5c6e7204f26dfd62bd0f95
SHA1: e2fac1c328751b278696a7f5e47345c545256b33
SHA256: cdd4542118f830abe702032f9b098c9731106b3021a1ce370e2885659ea2f0da
SSDeep: 48:+eNxeXAiQxhRiGVwFYnraz9DQJuzGRoKLLr2WOP5EJ5HKHWZStgS0F6Vb4wWv0iR:bXnzRi8yFSLLLr2NPW5Hd6v048v0I0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.12 KB MD5: d32e35d4fb27ab8e0f5133c00a586058
SHA1: 09c90090198876c0746a9fb2f85580ab73f5727c
SHA256: abebd863ca833d2ac6ff8e02e480fbd52ff5259c077bcbf77d5f2e72712f304e
SSDeep: 24:BjVbGMIUCZjkFBqXbNKpiFwg+iPeZio59mzdsA7AqS5FYcpFXny3o:BRIUCK2bNKpn7Kdsdlphy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 828 bytes MD5: 46b6e0163841e43737d8ec4da62478a5
SHA1: 74f20aec7df21743dc2234947e65d01a40b3b58f
SHA256: 168a76e7a50080b8b77f6e4b552b336accdbc4bcd15120cf8a86b5f42dec19cf
SSDeep: 24:v1P951m8Jc3XdcunFdE/hYAmIcGrFXny3o:v1j1mojuFdUPbrhy3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 796 bytes MD5: c70c6d547f290630cbc44bf7b9da3b2b
SHA1: d44292fd10b4c9965e8ef307796baef193fee9bd
SHA256: 7325cbd9f5ab8df9ea385d7c01010dbb9e98c570993ded57a4399f52d1989a31
SSDeep: 12:eORx73eqJFWaH+bunHSZJLm3RhbnBZXPszG2xutFWH1Inbs+1rmUKguXny34l:B3reqJ0ai3Ebn3k/xutgGsu+Xny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01630_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 540 bytes MD5: 84c41671202be6c4a344c37aca6dcdc5
SHA1: 44ffdd1ab5ba9a80cfd149f7c71e77988cde8b36
SHA256: d5edd7f1b7bb0673ef3c244046d67484d4a7ed203a46c8b2509ab1300d326f70
SSDeep: 12:HH/V+DedgiWWSIW9yyDUouk6+4u+rjnYUKguXny34l:HfVGghJuAEXny3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.86 KB MD5: 0bbbd77e4de121b97c9bd2f46bc74458
SHA1: 05c7299662e6d83ab1ca250e09d3b35352cf5fbd
SHA256: a87772654897bfd4a3b34673f4c9b5cb15f4aa0a9afd434648b746de9fecc13b
SSDeep: 384:WI89REoCU7gAhJvADntDGKU9W5ILUxTaO0gYmhrscLerW5io:N89RENSvcHU45XcmPBscLUW3
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.29 KB MD5: 8e3b98608ee0f126299c90def6a7484e
SHA1: f88aa829b1b2c21a9ed2a6aa0177844b3c6e2412
SHA256: 41c41cffd43c8375cb8df394b25e4644069aa48ddc504a4ca3dc5d854d8c2240
SSDeep: 96:w6p8wRAIv0nJ8eHfITh7Ax5zTcGHGu/pnWIJe953DDCavl5DnV5MSRIT8HW0o:Np8wRJ0iBTGHHGuVzerOavHDnwSRIT8O
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 3.42 KB MD5: fde92f16c6a69d0f532ada533b511cf2
SHA1: ef4e00ea453768ee51d82c0d4abb31c89f7f3386
SHA256: a469ff1d863b7d476dcf9a4d6c7fa0ed09d31e2a360191e648412e775481f2d8
SSDeep: 96:JouAB8o3C7wrltmChUHJfPXVPagi0h5kEU9wnT8GW0o:GuAXr3aJfPX5aX0hNbTq0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 1.59 KB MD5: ae99fce1b27ea04c56d414a07bbe793b
SHA1: 06fc9350c9327312eb7059399b01a56374d94ec5
SHA256: 7cada96f77a37b2f50a5dbebd3aefc5056eb7c69446b1467ac6e194a2f1c1312
SSDeep: 48:4RNsFLFI+3fJEnp66a6iFWpWUd+voScfAohy3o:4RGLFI0fJmp642WsUd+sfAoh0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01772_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.48 KB MD5: f4989ef76f40dfa7e040cfedebf71e97
SHA1: 5b33e739f9729c0a55146b6971beecbec70fb2a0
SHA256: cbecbd627c041c56892804545664560801005ede34a2d2e8ff3d16ac8886c0e1
SSDeep: 48:vQvgKXjZ+s/wjCLk3YshdOFIQPs7kN+gjenqgoD46QD/Cy3o:MzTVoj9IshEOQ07kN+goqvCD/C0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.98 KB MD5: 541b6ded8fb91adc012af967909aeb60
SHA1: 15cc10ae5663b1d62e8c17868f8c66263048e156
SHA256: 06092cbb250c98ad1ccd6145d20d1fc45a2eba2982133a751aa3313ead6f2e2e
SSDeep: 384:SOS+v+Ygqca8pcLvByDE5XKRvlZK7TKvjo:IuEtaC6ByP5I
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.87 KB MD5: a8bf1f4ae5b70a8c44bbf15728860c88
SHA1: da89067783e69bacfec75f3c12fd8859e9643498
SHA256: 1f913391272149719a8c441963cbc2335204320acf64ecf700270888aa812189
SSDeep: 48:lCkSwIbV9787jEz8jkexRlqvq92RBF/bXRsON7CTh3VvJt1DBgAbEFQAPcqQYUxv:lCkSw8a7jU84eobFTXRsON7qhVJtkAcU
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.03 KB MD5: c07c54ab3ce0cd255fe37d51b6935efd
SHA1: ba5f56fc5790d652c6081220e28b36245d202ca0
SHA256: 57c3a27a10cb4662e9916ad228e442a5a50ea2a4c952f0addea04f6799615463
SSDeep: 192:ehTSmSBAjiVwrx+T+E01BQGDwBmjIzM6gvq40o:aiVwrYT+E012c0Y6giPo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 13.86 KB MD5: 5f782f907703c5566c178f34293b06f4
SHA1: 321a6b545d9d5a9c3abea55dca01b315c4bb5c04
SHA256: e858e9dfc9b3857fe82a9810ae7cba55ae7376b2f2cc3c061a01757cda60f4ec
SSDeep: 384:Du78TipzosalC6tvUZJ2naeqwl7lGwxTQBq4xZWo:i78TipkblCSvVaeqwVNxckMn
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.86 KB MD5: 117a4d9567913ae031f1cb3193139e99
SHA1: 0074cb898141e04a091a15107dad1ab017bd0063
SHA256: 4d7e4ddb61ba5c05118941e4a07ffb87dc1e5eb14a4f922efab196e3a988c5ae
SSDeep: 192:T178M4njG+wLMyQFtZyX5LetTp+de6jo4cXwzhyOW1Me0o:Tt4njG+wLMjFtZmqtCe6AXktW1Mlo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.46 KB MD5: a562175da00853ae481a66d63065557c
SHA1: b33c0ea28162802723f6114a1ba24c8ec951165d
SHA256: c32fe7314365c2252f5c1ef388102fa3f0a9e3f3eebd8fbbbf8394c4c2ca7979
SSDeep: 48:E8DfrmaHSrOuAaql/CvqwXcZCs+Dx0QF/wYYjXmPgXMOy3o:EY6ViuAaAURMsJCe47jX+O0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 988 bytes MD5: a257a72175304b6d264e7db860a12a17
SHA1: 0f9e388197ce244732d0826b987004f44d1d76e5
SHA256: db61ef275acadabd7b2cdf9ef0bebcaeefff6c6c925379c9404b96b364a888b8
SSDeep: 24:xwBGkdotslxo75irFi9YdffDO9hYIpF6eOiabAwXny3o:xwBGkdotjVir/1DOU0UbAay3o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.14 KB MD5: 139bb2edcca5cce66f0b8cc2de7b4beb
SHA1: c9452f4dfb31dfabc46edbee64516923c8cbd15f
SHA256: d8cdc82f203a92bd0fb05d72360ad0903fb3462f62d6a03c495e1d762fd0e824
SSDeep: 384:E7Izl+UqKjzyvcjHx5wUgmxlyDq9wxKb6cgfl90gxTyKo:EAQzI5wmyO9wxKex992
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 2.28 KB MD5: c1e0745ff099403d28946f4f6a47a926
SHA1: b2a81ee5e5eed2791bb645a1703ae02f3b7cb722
SHA256: 9abef66300f2e3a69bacb40b76c465d713e5718596b789d5665f3f56b7c05818
SSDeep: 48:dgGXhGDoETUjvkMBXqE1V+ptQsnhDk64c/aRltwZoXnlTjXS06Aky3o:OGXhGsEYjsMvA0Uk4iRXMOnJSJAk0o
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.00 KB MD5: 71429652f9a5e24991a4c0f7dfea7a8c
SHA1: ded80be899fa419a08fbc1bcb75a98aac992c270
SHA256: a44fe3294cb8a451ec98b6e078b062e2c523b709370fb60eef49fd9f0ce849b3
SSDeep: 192:otsDCX+SWO4naNnF6iWcGLYGwArrzH+R7w2FdzVwLZ0o:qht4naNnFTWcGsGwAr3H+R7vFdgWo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 17.67 KB MD5: 2b133f4499815a1703cc07a3ee26e4f6
SHA1: dd273ab1a0c61be17c713954e454a580dce9877d
SHA256: 1c4609e8d1fc2932f7c74b240f3fa4e4bebaee8cd1e4801b78b12fe8f841f40d
SSDeep: 384:SCDA3nKqF6IEvlQmcp2Iy5eufEhBDcKlQ1AI3eeEYHKS/PXkNm3gM2OwUMo:SBnXtEU0p+ccAALeEm/MNLMhw2
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 29.78 KB MD5: 6ff68ecde7637c362013bf4314a75a37
SHA1: 4342f8f27d8ed6a1e767330599ccfa2aba846079
SHA256: bd8039d0a5b2986a77b6b2b4b072948866ce05357314d5d2de515551967038c5
SSDeep: 768:49KYKDmpONj/zGVyWwpRn2PVyXwBbVupDYzHc99lNp5bhAnFjN7:4YiqkpPVySV+DWcbR51aFj9
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 28.76 KB MD5: 59859b90e83e9011b046d878a98dc91a
SHA1: 2ea0a437a7c7bb7b380d4bfa2215d3621abb671c
SHA256: 0aeace9789c74bc99444e84315d1ab856ae2f712afef9825693648135038a642
SSDeep: 768:ATPjVHt037fZBTPD2/J7NXQ2J07RYEl8onL:+Sr+XQ2X08+
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 11.95 KB MD5: 403691ddd8a7f01949e5d71a04561b01
SHA1: bb05c3ff45491acd598a79f1e622fb3a31e09aa3
SHA256: 38bdaad4c3bd113da49113317599f16d764554d5963c0d492621249fd242fc0e
SSDeep: 192:QTHx++yt7RxSM4tCbRdOvjcwKwSDvYhx3m9dICM5yznEWqd7Ph+drbx7sQpPlPav:rHxsCFXvYD3m9dYEEjd7Pybx7rpPlPBo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 36.75 KB MD5: 73f0bd2e413eccce8b3d63a6acb42cb8
SHA1: 068ef65631753354ccd1a6273cc1b3eb184c3182
SHA256: 9776389a3f26608ce21b410345151afd88707ae879d7a6d602914f5cab5c0c3f
SSDeep: 768:DS6/Ly8++IQ7vM69zykgQBhldIhcM+r2ZDyHC4ax3PqqgYxjs:DS6/Ll7vjNtvbJreD2CVWYNs
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 7.01 KB MD5: 3400d661ee7b0554ca8d2736071e15fd
SHA1: 1ca5bee8c5a06c24a10993fa17a979d6dee5ed95
SHA256: 037b09273d28eb00e88d351b9c7859e6bf2e6941c75cc9f1e0229efe447af73e
SSDeep: 192:En/UNIZFDUZqGwBrFFNValUoWMVc5qow30o:En/DbUZqG4d4pUwko
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00222_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 12.31 KB MD5: a81874b75309b22a6b755639262ee1a5
SHA1: 907bacd255938f833e42751e625ff3ac0825ee25
SHA256: 7d002b6eee15982a7c79d97351ac02cf9567aefaf7b6abf4568e815b6b6ffa2b
SSDeep: 192:iRK3TDobiCYK1NV0+PSBGc1enkzv962Jb7svIFIvdVv2ypTYnN9Q/7ioLEIz7Yt3:iRK3TDoXe+8/e8JMwO52ruGoLHXVo
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 15.73 KB MD5: 064cc899079e1a26845dd4a78a2a1bbd
SHA1: 107d208a20a1d1b9ddf0a6189a789b57a081a4b0
SHA256: d9b1214e666f50081aa3e81318ef0966aa44e4c6e8562150d794a6f66a7b4980
SSDeep: 384:oaXtn3emDi7qElt2ocLrC4AptPBDXTym9EkrTZBZ4208m9Tmd5go:oktbm55Oe4KPBD+m9/D+p9qr
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 18.01 KB MD5: 21d970e3875dbdaabe8999c41cad1b0b
SHA1: 8b4d0c1926865ec6c9e3cc632f293713e7ae165e
SHA256: 3109f20207e96092b4e0bfe76b1eb89ac4e30d38371fd960f290e329ee186309
SSDeep: 384:39Gp2niGDPUYb4cj/cKw4p7OePS11/WUPPhNiv3l/9gW57VVo:N25EPb9FzKee/hPhN4hZ70
False
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: c882e6e41122c23dcc820e7170ef0067
SHA1: 30daabd74437482602a78154d47de4446accc1f8
SHA256: ee9f96e3cc8002b2495844e3c5683219d8003aa6ebf54b3137cb37b5abc4a74b
SSDeep: 1536:ElVGVmxuzMJ0ApW+mkGBzB+tGaO/b4vXjWhgAOmLYgfg1sFM:UG5zMCAYkGn8zgsYCAze
False
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.34 KB MD5: 634aaa83dcea85cd4f57eeaa9efe87f4
SHA1: e3ee7fe95cfdb6d092ddbb66e5f7a3f4871dfa1a
SHA256: 80a76f8a0bdd7629146bd218bc8ab471b26472c475086380d386e1d981e6c132
SSDeep: 1536:25nbYOb5Hw5s5itDTmpoMDYCzi+wJI8NjSiI770eT/YKwA/Xrhdk:4bYgyK5AqoMDYCWVSD6K7k
False
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: 11bf722770f6a560c4bd91046508bfab
SHA1: 1b2bf2ee570d55b9a8f4ddd5bc4c00b09fe2e406
SHA256: 560eacc674e8665bc3ac13afeb3bc21acbbcdfb0bd19deecb5cf637f4a380cef
SSDeep: 1536:VSy7EyqQTkg+7SLDUQeDdLTY0SQZqC2WJHoGmJ:8yEyVs7SvU15LTYMICLHoGmJ
False
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: d29c7111cc035b7fdc7a77f30d0ca3c5
SHA1: 2abd2b01110fdcb3c4243dd34bc75cc10a54aa44
SHA256: d706d012389c909c7059ceafc3953bc9ec724ed2a72fbc11ed59fe30e37b2e3a
SSDeep: 1536:2DyfzhWi74Miy7JECu0Cl1aLMz5n6MRI8Bpd:2Dy7h/TJUlgG5PIApd
False
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: 7ab23323549ec7cd986e31f619a1f4ae
SHA1: ea143c876fbde0c2c00fad5ff83080182ccf02c3
SHA256: ec3360f2f9178604972b89fceba05515c0e7358cbea9c12e410facf6d5714b2d
SSDeep: 1536:Iz55nTUU9cjCoFTL5xf+xkPe1bAtHt2MoCIyN7Zco:Sf59cGoFjf+xkPe1it2MOdo
False
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.33 KB MD5: ab44c7521b82aceaf4c225965d88ee25
SHA1: edd71c326db8849e478cf6d4592d6e377d1b8774
SHA256: e81db3cfcfd0284a446e8d50681683fab9dd9a96435f3f90323dba69c45acd83
SSDeep: 1536:9wHmwdT4owJvBYKbn0lUP3OUulJscg2I5QUY7StpvE:9whT1+baUP3sRg2o87GdE
False
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: bee9641b620652f3186cb2621e0ac3c9
SHA1: 60cd43d6fd7111f6accc88350642f705dbda65bb
SHA256: 522cd737362be6510a438f4eba2e3cf10d3128991b43753f53bfee5b65409060
SSDeep: 1536:MLywo3qN12Upf2WDek5WNanjuyA6dlVzExHHKiAg:Mw6N12UpuAJ5/nOfnAg
False
C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: d83db986c2ffeae9f9a72e67173c74b9
SHA1: 0e28e545d2b4e5610b6fe2eed80c42926adfcb0c
SHA256: 29aae65f832ca0c0a680db0ffa1794522da7b72897f0ff0444418c2832d5e8af
SSDeep: 1536:ExhhN+dVI/CaTyQDLSJ36BOZ2lMpGlMEKxpMMXCKag6bk:+YdVIKa2kE3e+UlQPHXn/
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 4.21 KB MD5: 3119b57b6f4d6aafea1b2c424eea05cc
SHA1: 058d48d0a4b71bed0115f9b760214b1df50872d1
SHA256: e5b625a2fe5165d59a0b35676f9a8d928279d0c7cf913ba9b09ff427ea821512
SSDeep: 96:B1x9GNTknUCn3pKzRThYbBpFZC1nCxXb9N/IFVsmM+7abZmC1rxdJ0o:Tx9uTLCn5KzY1wnCxJoV3abZmmJ0o
False
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.30 KB MD5: fa3c0dfaaaa177fb07341513485b74ec
SHA1: e33b647a179b66c64468709520ea718df02056ab
SHA256: d6152ef807bdb0765a70ed04a184fe8eb7c0d5f1536c84944988b3544cf89520
SSDeep: 1536:tRwt2RzKTsENyS+j7A+8AptTRWIC1MF0bsgKD266PSo:tRwcRzG6jp/Ri1MFysgKD2TSo
False
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.31 KB MD5: e34bb8630b3538440252d1bacc331e16
SHA1: 68dec7bcb2123c38620359ebc63a3efb4c62b5f1
SHA256: 0a88f37986afc5d14a61aebbf4482df95e14e71c92f0678a9a25d6815890d887
SSDeep: 1536:51GMb5D5N95taeexkp/XEtokKkVIe8p2bFrxJL+NdPnz:3GMbx5jaeexkVUykKnENXML
False
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.32 KB MD5: 3e131a00c5483c4cc5320961c24c1ecb
SHA1: d1a31986493130ebd023c3d63d90820e0cfe77f9
SHA256: f1198b23ea9f977bf60555f7066d84a5805b87b3885bdf944eba6fd17605442f
SSDeep: 1536:SEPJrHits817AYLXzfT+OTzD4WkuMP/ZNSt7qAtqLiuODS:HPJ7itiRxvPPSZqXL5ODS
False
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat 68.29 KB MD5: 7099fa271a697de7c93b173cf408adaa
SHA1: e6dd9325faf070a45d25aa394318d3e42d578e88
SHA256: 0b794100ebbe59f3461feb14e0ac15b43dbe4c25411ed24e875474482c8d566c
SSDeep: 1536:pEy9mLeLpBKiRlF2pKxR3Id0e5ZPhfWJ1xMJCRjN+:iLKpBVRWKH4d0e5ZRoxXRc
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 8.59 KB MD5: c20c43fd2021cf7550d084c7810e31f3
SHA1: 890f65528f22a8a95ff347a53db02629b441fea8
SHA256: 344bfd598b3b17a7a85f26f32c9815a8e38834620f3e43b7e5b37e6a31776794
SSDeep: 192:m6U4rL++YrVqoDhSKuGILJdSgzy6P0sMCewOOCkWD54j2iWTl0o:7L+rVTpurL3FVcsDOOCkoOj2iUio
False
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00336_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat 6.17 KB MD5: 4dab8ec9c7a00f046ce9bedf3b15860e
SHA1: 7605f3213495b5314d2f3efb85e0ea3e6ca864c7
SHA256: a606cd509874f0352dac389cadee66a53ae5ae63227e9ff156ba2ecc2662f19d
SSDeep: 192:QqK9bx9uYcxebz/ys+lRCHeJHNOBbBlmUHGH0o:Zod9u/xQzKs+njOVHm3Uo
False
Threads
Thread 0x408
434 0
»
Category Operation Information Success Count Logfile
Module Load module_name = kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x75ea51b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x75ea50d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x75efee40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x75efed70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MoveFileW, address_out = 0x75ede500 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x75efef40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x75ea5090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x75efef10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x75ea3cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCommandLineW, address_out = 0x75ea4cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x75ed32c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameA, address_out = 0x75ed3780 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x75efeb70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenW, address_out = 0x75ea6c70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenA, address_out = 0x75ea6c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x75efea10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x75efeca0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x75ea0d20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x75efdd50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x75efed40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x75ea6b10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSectionAndSpinCount, address_out = 0x75efebb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x75ea6760 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x77bfb250 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x75eff090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x75efed10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x75efebf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x77bfb2d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x75efec80 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x75ea6bf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x75ea6bd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x77bdfb90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x75efec20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x75efeab0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersion, address_out = 0x75ea56c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x75ea46b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x75ea4a40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceCounter, address_out = 0x75ea5da0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceFrequency, address_out = 0x75ea5dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x75efea20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x75eff100 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x75eff020 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x75eff180 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointerEx, address_out = 0x75eff130 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x75eff0e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x75efedf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x75ea51f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x77bef630 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77bf2dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x75ea57f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreatePipe, address_out = 0x75ea4590 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetHandleInformation, address_out = 0x75efeae0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x75ea4610 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringW, address_out = 0x75ea4430 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringA, address_out = 0x75ea4410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x75ea5cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x75ea67e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x75ea54e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x75ea67a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x75ea5010 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x75ededc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x75edf8f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x75edf750 True 1
Fn
Module Load module_name = advapi32.dll, base_address = 0x761b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x761ce580 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x761ce5a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x761cf530 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x761ced60 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x761cefb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x761cee90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenSCManagerW, address_out = 0x761d0540 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenServiceW, address_out = 0x761cfa20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CloseServiceHandle, address_out = 0x761cfc00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ControlService, address_out = 0x761e26d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = QueryServiceStatus, address_out = 0x761d2380 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumDependentServicesW, address_out = 0x761e2f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumServicesStatusExW, address_out = 0x761cfc80 True 1
Fn
Module Load module_name = user32.dll, base_address = 0x74b70000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SystemParametersInfoW, address_out = 0x74b9f210 True 1
Fn
Module Load module_name = Shell32.dll, base_address = 0x76480000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x765e4730 True 1
Fn
Module Load module_name = ntdll.dll, base_address = 0x77bb0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x77c22070 True 1
Fn
Module Load module_name = mpr.dll, base_address = 0x74500000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetCloseEnum, address_out = 0x74502640 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetOpenEnumW, address_out = 0x74502790 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetEnumResourceW, address_out = 0x74502410 True 1
Fn
Module Load module_name = ws2_32.dll, base_address = 0x746a0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = WSAStartup, address_out = 0x746a5b40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = socket, address_out = 0x746b4510 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = send, address_out = 0x746a5030 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = recv, address_out = 0x746b0c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = connect, address_out = 0x746a5410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = closesocket, address_out = 0x746b0910 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = gethostbyname, address_out = 0x746d6cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = inet_addr, address_out = 0x746b9160 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = ntohl, address_out = 0x746a49d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htonl, address_out = 0x746a49d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htons, address_out = 0x746b8ff0 True 1
Fn
System Get Time type = Performance Ctr, time = 13390446661 True 1
Fn
System Get Time type = Ticks, time = 133875 True 3
Fn
System Get Info type = Operating System True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE False 1
Fn
Mutex Create mutex_name = Global\syncronize_1TPBM0A True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE False 1
Fn
Mutex Create mutex_name = Global\syncronize_1TPBM0U True 1
Fn
System Get Info type = Operating System True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\hgaibc.exe, file_name_orig = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 32767 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
File Create filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\WINDOWS\System32\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\WINDOWS\System32\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run True 1
Fn
Registry Write Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, value_name = hgaibc.exe, data = C:\WINDOWS\System32\hgaibc.exe, size = 60, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
File Create filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
File Create filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
Process Create process_name = C:\WINDOWS\system32\cmd.exe, os_pid = 0xf8c, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Write size = 65 True 1
Fn
Data
Module Get Filename process_name = c:\users\fd1hvy\desktop\hgaibc.exe, file_name_orig = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 32767 True 1
Fn
Module Get Filename process_name = c:\users\fd1hvy\desktop\hgaibc.exe, file_name_orig = C:\Users\FD1HVy\Desktop\hgaibc.exe, size = 32767 True 1
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0xf78
4186 0
»
Category Operation Information Success Count Logfile
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
For performance reasons, the remaining 632 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xf58
1 0
»
Category Operation Information Success Count Logfile
System Get Computer Name result_out = NQDPDE True 1
Fn
Thread 0xa8c
105 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 134781 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Get Time type = Ticks, time = 135000 True 1
Fn
System Get Time type = Ticks, time = 136343 True 2
Fn
System Get Time type = Ticks, time = 136546 True 1
Fn
System Get Time type = Ticks, time = 136937 True 1
Fn
System Get Time type = Ticks, time = 137062 True 1
Fn
System Get Time type = Ticks, time = 137937 True 2
Fn
System Get Time type = Ticks, time = 138671 True 1
Fn
System Get Time type = Ticks, time = 139218 True 2
Fn
System Get Time type = Ticks, time = 139562 True 1
Fn
System Get Time type = Ticks, time = 140953 True 2
Fn
System Get Time type = Ticks, time = 141234 True 1
Fn
System Get Time type = Ticks, time = 142265 True 2
Fn
System Get Time type = Ticks, time = 142437 True 1
Fn
System Get Time type = Ticks, time = 142546 True 1
Fn
System Get Time type = Ticks, time = 142656 True 1
Fn
System Get Time type = Ticks, time = 142765 True 1
Fn
System Get Time type = Ticks, time = 142875 True 1
Fn
System Get Time type = Ticks, time = 143000 True 1
Fn
System Get Time type = Ticks, time = 143109 True 1
Fn
System Get Time type = Ticks, time = 143218 True 1
Fn
System Get Time type = Ticks, time = 143328 True 2
Fn
System Get Time type = Ticks, time = 143437 True 1
Fn
System Get Time type = Ticks, time = 143546 True 1
Fn
System Get Time type = Ticks, time = 143656 True 1
Fn
System Get Time type = Ticks, time = 143828 True 1
Fn
System Get Time type = Ticks, time = 143937 True 1
Fn
System Get Time type = Ticks, time = 144046 True 1
Fn
System Get Time type = Ticks, time = 144171 True 1
Fn
System Get Time type = Ticks, time = 144281 True 1
Fn
System Get Time type = Ticks, time = 144390 True 2
Fn
System Get Time type = Ticks, time = 144500 True 1
Fn
System Get Time type = Ticks, time = 144609 True 1
Fn
System Get Time type = Ticks, time = 144750 True 1
Fn
System Get Time type = Ticks, time = 144859 True 1
Fn
System Get Time type = Ticks, time = 144968 True 1
Fn
System Get Time type = Ticks, time = 145078 True 1
Fn
System Get Time type = Ticks, time = 145187 True 1
Fn
System Get Time type = Ticks, time = 145328 True 1
Fn
System Get Time type = Ticks, time = 145437 True 2
Fn
System Get Time type = Ticks, time = 145546 True 1
Fn
System Get Time type = Ticks, time = 145671 True 1
Fn
System Get Time type = Ticks, time = 145781 True 1
Fn
System Get Time type = Ticks, time = 145890 True 1
Fn
System Get Time type = Ticks, time = 146000 True 1
Fn
System Get Time type = Ticks, time = 146109 True 1
Fn
System Get Time type = Ticks, time = 146218 True 1
Fn
System Get Time type = Ticks, time = 146328 True 1
Fn
System Get Time type = Ticks, time = 147015 True 2
Fn
System Get Time type = Ticks, time = 147468 True 1
Fn
System Get Time type = Ticks, time = 147796 True 1
Fn
System Get Time type = Ticks, time = 148546 True 2
Fn
System Get Time type = Ticks, time = 149328 True 1
Fn
System Get Time type = Ticks, time = 149921 True 2
Fn
System Get Time type = Ticks, time = 150375 True 1
Fn
System Get Time type = Ticks, time = 151343 True 2
Fn
System Get Time type = Ticks, time = 152031 True 1
Fn
System Get Time type = Ticks, time = 152562 True 2
Fn
System Get Time type = Ticks, time = 153421 True 1
Fn
System Get Time type = Ticks, time = 154203 True 2
Fn
System Get Time type = Ticks, time = 154765 True 1
Fn
System Get Time type = Ticks, time = 155234 True 2
Fn
System Get Time type = Ticks, time = 156093 True 1
Fn
System Get Time type = Ticks, time = 156703 True 2
Fn
System Get Time type = Ticks, time = 157109 True 1
Fn
System Get Time type = Ticks, time = 157562 True 1
Fn
System Get Time type = Ticks, time = 158609 True 2
Fn
System Get Time type = Ticks, time = 159328 True 1
Fn
System Get Time type = Ticks, time = 160390 True 2
Fn
System Get Time type = Ticks, time = 161046 True 1
Fn
System Get Time type = Ticks, time = 161703 True 2
Fn
System Get Time type = Ticks, time = 162171 True 1
Fn
System Get Time type = Ticks, time = 162312 True 1
Fn
System Get Time type = Ticks, time = 162703 True 1
Fn
System Get Time type = Ticks, time = 162890 True 2
Fn
System Get Time type = Ticks, time = 163031 True 1
Fn
System Get Time type = Ticks, time = 163281 True 1
Fn
System Get Time type = Ticks, time = 163390 True 1
Fn
System Get Time type = Ticks, time = 163515 True 1
Fn
System Get Time type = Ticks, time = 163640 True 1
Fn
System Get Time type = Ticks, time = 163750 True 1
Fn
Thread 0xd14
105 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 134781 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Get Time type = Ticks, time = 135000 True 1
Fn
System Get Time type = Ticks, time = 136343 True 2
Fn
System Get Time type = Ticks, time = 136546 True 1
Fn
System Get Time type = Ticks, time = 136937 True 1
Fn
System Get Time type = Ticks, time = 137062 True 1
Fn
System Get Time type = Ticks, time = 137953 True 2
Fn
System Get Time type = Ticks, time = 138671 True 1
Fn
System Get Time type = Ticks, time = 139218 True 2
Fn
System Get Time type = Ticks, time = 139562 True 1
Fn
System Get Time type = Ticks, time = 140953 True 2
Fn
System Get Time type = Ticks, time = 141234 True 1
Fn
System Get Time type = Ticks, time = 142265 True 2
Fn
System Get Time type = Ticks, time = 142437 True 1
Fn
System Get Time type = Ticks, time = 142546 True 1
Fn
System Get Time type = Ticks, time = 142656 True 1
Fn
System Get Time type = Ticks, time = 142765 True 1
Fn
System Get Time type = Ticks, time = 142875 True 1
Fn
System Get Time type = Ticks, time = 143000 True 1
Fn
System Get Time type = Ticks, time = 143109 True 1
Fn
System Get Time type = Ticks, time = 143218 True 1
Fn
System Get Time type = Ticks, time = 143328 True 2
Fn
System Get Time type = Ticks, time = 143437 True 1
Fn
System Get Time type = Ticks, time = 143546 True 1
Fn
System Get Time type = Ticks, time = 143656 True 1
Fn
System Get Time type = Ticks, time = 143828 True 1
Fn
System Get Time type = Ticks, time = 143937 True 1
Fn
System Get Time type = Ticks, time = 144046 True 1
Fn
System Get Time type = Ticks, time = 144171 True 1
Fn
System Get Time type = Ticks, time = 144281 True 1
Fn
System Get Time type = Ticks, time = 144390 True 2
Fn
System Get Time type = Ticks, time = 144500 True 1
Fn
System Get Time type = Ticks, time = 144609 True 1
Fn
System Get Time type = Ticks, time = 144750 True 1
Fn
System Get Time type = Ticks, time = 144859 True 1
Fn
System Get Time type = Ticks, time = 144968 True 1
Fn
System Get Time type = Ticks, time = 145078 True 1
Fn
System Get Time type = Ticks, time = 145187 True 1
Fn
System Get Time type = Ticks, time = 145328 True 1
Fn
System Get Time type = Ticks, time = 145437 True 2
Fn
System Get Time type = Ticks, time = 145546 True 1
Fn
System Get Time type = Ticks, time = 145671 True 1
Fn
System Get Time type = Ticks, time = 145781 True 1
Fn
System Get Time type = Ticks, time = 145890 True 1
Fn
System Get Time type = Ticks, time = 146000 True 1
Fn
System Get Time type = Ticks, time = 146109 True 1
Fn
System Get Time type = Ticks, time = 146218 True 1
Fn
System Get Time type = Ticks, time = 146328 True 1
Fn
System Get Time type = Ticks, time = 147015 True 2
Fn
System Get Time type = Ticks, time = 147468 True 1
Fn
System Get Time type = Ticks, time = 147843 True 1
Fn
System Get Time type = Ticks, time = 148546 True 2
Fn
System Get Time type = Ticks, time = 149328 True 1
Fn
System Get Time type = Ticks, time = 149921 True 2
Fn
System Get Time type = Ticks, time = 150375 True 1
Fn
System Get Time type = Ticks, time = 151343 True 2
Fn
System Get Time type = Ticks, time = 152031 True 1
Fn
System Get Time type = Ticks, time = 152562 True 2
Fn
System Get Time type = Ticks, time = 153421 True 1
Fn
System Get Time type = Ticks, time = 154203 True 2
Fn
System Get Time type = Ticks, time = 154765 True 1
Fn
System Get Time type = Ticks, time = 155234 True 2
Fn
System Get Time type = Ticks, time = 156093 True 1
Fn
System Get Time type = Ticks, time = 156703 True 2
Fn
System Get Time type = Ticks, time = 157109 True 1
Fn
System Get Time type = Ticks, time = 157562 True 1
Fn
System Get Time type = Ticks, time = 158609 True 2
Fn
System Get Time type = Ticks, time = 159328 True 1
Fn
System Get Time type = Ticks, time = 160390 True 2
Fn
System Get Time type = Ticks, time = 161046 True 1
Fn
System Get Time type = Ticks, time = 161703 True 2
Fn
System Get Time type = Ticks, time = 162171 True 1
Fn
System Get Time type = Ticks, time = 162312 True 1
Fn
System Get Time type = Ticks, time = 162703 True 1
Fn
System Get Time type = Ticks, time = 162890 True 2
Fn
System Get Time type = Ticks, time = 163031 True 1
Fn
System Get Time type = Ticks, time = 163281 True 1
Fn
System Get Time type = Ticks, time = 163390 True 1
Fn
System Get Time type = Ticks, time = 163515 True 1
Fn
System Get Time type = Ticks, time = 163640 True 1
Fn
System Get Time type = Ticks, time = 163750 True 1
Fn
Thread 0xef8
5635 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\SetupResources.dll, type = size, size_out = 156 True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, size = 1048560, size_out = 156 True 1
Fn
Data
File Write filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 129 True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini, type = file_attributes True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini, size = 1048560, size_out = 129 True 1
Fn
Data
File Write filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 144 True 1
Fn
Data
File Read filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\$Recycle.Bin\S-1-5-18\desktop.ini True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = size, size_out = 129 True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = file_attributes True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, size = 1048560, size_out = 129 True 1
Fn
Data
File Write filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 144 True 1
Fn
Data
File Read filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\eula.rtf, type = size, size_out = 7567 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1025\eula.rtf, size = 1048560, size_out = 7567 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7568 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1025\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, type = size, size_out = 86284 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, size = 1048560, size_out = 86284 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 86288 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1032\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1032\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, type = size, size_out = 77232 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, size = 1048560, size_out = 77232 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 77248 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1033\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1033\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, type = size, size_out = 77022 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, size = 1048560, size_out = 77022 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 77024 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1035\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1035\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\eula.rtf, type = size, size_out = 6851 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1037\eula.rtf, size = 1048560, size_out = 6851 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6864 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1037\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1037\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, type = size, size_out = 72076 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, size = 1048560, size_out = 72076 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 72080 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1037\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1037\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\LocalizedData.xml, type = size, size_out = 86442 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1038\LocalizedData.xml, size = 1048560, size_out = 86442 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 86448 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1040\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1038\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, type = size, size_out = 80060 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, size = 1048560, size_out = 80060 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80064 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1040\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\eula.rtf, type = size, size_out = 10125 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1041\eula.rtf, size = 1048560, size_out = 10125 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10128 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1041\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1041\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, type = size, size_out = 65238 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, size = 1048560, size_out = 65238 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 65248 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1042\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1042\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\eula.rtf, type = size, size_out = 3546 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1043\eula.rtf, size = 1048560, size_out = 3546 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3552 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1043\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1043\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, type = size, size_out = 79634 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, size = 1048560, size_out = 79634 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 79648 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1043\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1043\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, type = size, size_out = 201796 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, size = 1048560, size_out = 201796 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 201808 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Client\Parameterinfo.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\UiInfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\UiInfo.xml, type = size, size_out = 39050 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\UiInfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\UiInfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Extended\UiInfo.xml, size = 1048560, size_out = 39050 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 39056 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\ParameterInfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Extended\UiInfo.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.xsd, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.xsd, type = size, size_out = 30120 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.xsd, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.xsd, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\SetupUi.xsd, size = 1048560, size_out = 30120 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30128 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\SetupUi.xsd, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\SetupUi.xsd True 1
Fn
File Create filename = C:\588bce7c90097ed212\Strings.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Strings.xml, type = size, size_out = 14084 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Strings.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Strings.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Strings.xml, size = 1048560, size_out = 14084 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14096 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Strings.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Strings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Strings.xml True 1
Fn
File Create filename = C:\BOOTSECT.BAK, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\BOOTSECT.BAK, type = size, size_out = 8192 True 1
Fn
File Get Info filename = C:\BOOTSECT.BAK, type = file_attributes True 1
Fn
File Get Info filename = C:\BOOTSECT.BAK.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\BOOTSECT.BAK, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\BOOTSECT.BAK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\BOOTSECT.BAK, size = 1048560, size_out = 8192 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8208 True 1
Fn
Data
File Read filename = C:\BOOTSECT.BAK, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, size = 236 True 1
Fn
Data
File Delete filename = C:\BOOTSECT.BAK True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = size, size_out = 27045 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = size, size_out = 48936 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = size, size_out = 46622 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, type = size, size_out = 180172 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, type = size, size_out = 181964 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\split.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, type = size, size_out = 3529 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, size = 1048560, size_out = 645 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 656 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg, type = size, size_out = 4222 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\HandPrints.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm, type = size, size_out = 232 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Peacock.htm, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm, type = size, size_out = 233 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.htm, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg, type = size, size_out = 1920 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Roses.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg, type = size, size_out = 4734 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\ShadesOfBlue.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, type = size, size_out = 7505 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, size = 1048560, size_out = 15276 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15280 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, type = size, size_out = 12250 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, size = 1048560, size_out = 12250 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12256 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 252 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, type = size, size_out = 4226 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, size = 1048560, size_out = 4226 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, type = size, size_out = 955 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, size = 1048560, size_out = 955 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat, size = 960 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\Welcome.html True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\AppXManifest.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\AppXManifest.xml, type = size, size_out = 5944055 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\AppXManifest.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\AppXManifest.xml, destination_filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786700 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF, type = size, size_out = 3140 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF, size = 1048560, size_out = 3140 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3152 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, type = size, size_out = 15308 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, size = 1048560, size_out = 15308 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, type = size, size_out = 4955 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, size = 1048560, size_out = 4955 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, type = size, size_out = 13254 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, size = 1048560, size_out = 13254 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00164_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, type = size, size_out = 5375 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, size = 1048560, size_out = 5375 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5376 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, type = size, size_out = 3120 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, size = 1048560, size_out = 3120 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3136 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00176_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, type = size, size_out = 4734 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, size = 1048560, size_out = 4734 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4736 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, type = size, size_out = 14428 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, size = 1048560, size_out = 14428 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14432 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00932_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, type = size, size_out = 3344 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, size = 1048560, size_out = 3344 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01039_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF, type = size, size_out = 1832 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF, size = 1048560, size_out = 1832 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1840 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 27858 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF, size = 1048560, size_out = 27858 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27872 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, type = size, size_out = 3012 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, size = 1048560, size_out = 3012 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, type = size, size_out = 7540 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, size = 1048560, size_out = 7540 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, type = size, size_out = 2108 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, size = 1048560, size_out = 2108 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2112 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, type = size, size_out = 3416 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, size = 1048560, size_out = 3416 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3424 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, type = size, size_out = 8492 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, size = 1048560, size_out = 8492 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, type = size, size_out = 7804 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, size = 1048560, size_out = 7804 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, type = size, size_out = 3348 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, size = 1048560, size_out = 3348 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04326_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, type = size, size_out = 4808 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, size = 1048560, size_out = 4808 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, type = size, size_out = 28948 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, size = 1048560, size_out = 28948 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 28960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, type = size, size_out = 22516 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 22516 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 22528 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, type = size, size_out = 16112 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 16112 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16128 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 4924 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF, size = 1048560, size_out = 4924 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4928 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07804_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, type = size, size_out = 24320 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, size = 1048560, size_out = 24320 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24336 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08758_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, type = size, size_out = 40206 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 40206 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 40208 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, type = size, size_out = 11058 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 11058 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11072 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 880 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 1696 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1712 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 4024 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00242_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 4708 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00252_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1736 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1744 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00254_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 2644 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2656 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00267_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 13102 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13104 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00390_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11500 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11504 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4408 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4416 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6256 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6272 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3350 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1044 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1056 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 12788 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5580 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5584 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1680 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00443_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3796 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00445_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2732 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2736 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01080_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1874 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1888 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4236 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5270 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 49546 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 49552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2966 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10326 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10336 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 31122 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31136 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2960 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2304 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01162_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2080 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2096 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01166_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2080 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2096 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01167_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2020 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01169_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2052 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2064 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01171_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1804 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01173_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3796 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2084 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2096 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11994 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 37390 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 37392 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15856 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15872 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00306_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 46814 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00306_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00306_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00306_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00543_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1472 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00543_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1488 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00543_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00543_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15164 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15168 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00965_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3964 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01191_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01657_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 30414 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01657_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30416 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01657_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01657_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02075_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4396 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02075_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4400 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02075_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02075_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02097_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1564 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02097_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1568 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02097_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02097_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3988 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4000 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02116_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02158_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1648 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02158_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1664 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02158_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02158_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00236_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3286 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00236_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3296 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00236_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00236_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00276_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00276_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00276_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00276_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00513_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 818 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00513_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 832 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00513_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00513_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13538 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00526_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00546_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3718 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00546_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3728 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00546_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00546_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00602_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1400 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00602_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1408 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00602_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00602_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00623_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10644 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00623_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10656 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00623_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00623_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1568 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1584 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00636_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00681_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00681_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00681_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00681_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00685_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4032 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00685_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4048 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00685_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00685_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01291_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15806 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01291_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01291_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01291_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01461_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5958 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01461_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01461_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01461_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2704 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02155_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1324 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1328 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02166_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02282_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7932 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02282_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7936 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02282_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02282_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02312_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4970 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02312_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02312_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02312_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00005_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 23300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00005_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00005_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00005_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15852 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15856 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
For performance reasons, the remaining 206 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xefc
5306 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 40 True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log, size = 1048560, size_out = 40 True 1
Fn
Data
File Write filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48 True 1
Fn
Data
File Read filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 272 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, type = size, size_out = 74214 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, size = 1048560, size_out = 74214 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 74224 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1025\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1025\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, type = size, size_out = 80970 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, size = 1048560, size_out = 80970 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80976 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1029\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1029\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\eula.rtf, type = size, size_out = 3314 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1030\eula.rtf, size = 1048560, size_out = 3314 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3328 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1030\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1030\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, type = size, size_out = 77748 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, size = 1048560, size_out = 77748 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 77760 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1030\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1030\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\eula.rtf, type = size, size_out = 3419 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1031\eula.rtf, size = 1048560, size_out = 3419 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3424 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1031\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\eula.rtf, type = size, size_out = 4040 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1045\eula.rtf, size = 1048560, size_out = 4040 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4048 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1045\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\eula.rtf, type = size, size_out = 54456 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1049\eula.rtf, size = 1048560, size_out = 54456 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 54464 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1049\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1049\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\eula.rtf, type = size, size_out = 3865 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1053\eula.rtf, size = 1048560, size_out = 3865 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3872 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1053\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1053\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, type = size, size_out = 77680 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, size = 1048560, size_out = 77680 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 77696 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1053\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1053\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, type = size, size_out = 76818 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, size = 1048560, size_out = 76818 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 76832 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1055\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1055\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 4015 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2070\eula.rtf, size = 1048560, size_out = 4015 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4016 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2070\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2070\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, type = size, size_out = 79996 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, size = 1048560, size_out = 79996 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80000 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\3082\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3082\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, type = size, size_out = 93314 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, size = 1048560, size_out = 93314 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 93328 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Extended\Parameterinfo.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\header.bmp, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\header.bmp, type = size, size_out = 3628 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\header.bmp, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\header.bmp, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\header.bmp, size = 1048560, size_out = 3628 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3632 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\header.bmp, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\header.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\header.bmp True 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = size, size_out = 4662 True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, type = size, size_out = 4136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, size = 1048560, size_out = 4136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4144 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml, type = size, size_out = 4450 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, size = 1048560, size_out = 4450 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, size = 4464 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, size = 264 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, type = size, size_out = 84190 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi, type = size, size_out = 208408 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\delete.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi, type = size, size_out = 199994 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\join.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml, type = size, size_out = 1600388 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml, type = size, size_out = 903 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, type = size, size_out = 384 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, size = 1048560, size_out = 174 True 1
Fn
Data
File Write filename = C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 176 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\desktop.ini True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, type = size, size_out = 1423 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, size = 1048560, size_out = 1423 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1424 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, type = size, size_out = 8590 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, size = 1048560, size_out = 8590 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8592 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, type = size, size_out = 153 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, size = 1048560, size_out = 153 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, type = size, size_out = 165 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, size = 1048560, size_out = 165 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 176 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, type = size, size_out = 153 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, size = 1048560, size_out = 153 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, type = size, size_out = 168 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, size = 1048560, size_out = 168 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 176 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, type = size, size_out = 281 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, size = 1048560, size_out = 281 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 288 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\FileSystemMetadata.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, type = size, size_out = 36336 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, size = 1048560, size_out = 36336 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36352 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, type = size, size_out = 387356 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 387356 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 387360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, type = size, size_out = 496513 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 496513 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 496528 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, type = size, size_out = 253712 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 253712 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 253728 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, type = size, size_out = 1124942 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 76382 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 76384 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, type = size, size_out = 215883 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 215883 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 215888 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, type = size, size_out = 343329 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 343329 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 343344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, type = size, size_out = 357349 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 357349 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 357360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, type = size, size_out = 399528 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 399528 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 399536 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, type = size, size_out = 527958 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 527958 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 527968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml, type = size, size_out = 2173046 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml, destination_filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786714 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, type = size, size_out = 2344 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, size = 1048560, size_out = 2344 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2352 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, type = size, size_out = 2636 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, size = 1048560, size_out = 2636 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, type = size, size_out = 7668 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, size = 1048560, size_out = 7668 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7680 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04235_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, type = size, size_out = 7804 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, size = 1048560, size_out = 7804 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04267_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, type = size, size_out = 2492 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, size = 1048560, size_out = 2492 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04323_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, type = size, size_out = 3228 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, size = 1048560, size_out = 3228 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3232 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04355_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, type = size, size_out = 5004 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, size = 1048560, size_out = 5004 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, type = size, size_out = 26886 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, size = 1048560, size_out = 26886 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26896 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, type = size, size_out = 11636 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, size = 1048560, size_out = 11636 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00155_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, type = size, size_out = 16180 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, size = 1048560, size_out = 16180 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16192 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00173_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, type = size, size_out = 20454 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, size = 1048560, size_out = 20454 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20464 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, type = size, size_out = 15733 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, size = 1048560, size_out = 15733 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15744 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, type = size, size_out = 12982 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, size = 1048560, size_out = 12982 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12992 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, type = size, size_out = 2556 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, size = 1048560, size_out = 2556 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00262_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, type = size, size_out = 5272 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, size = 1048560, size_out = 5272 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00269_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, type = size, size_out = 3016 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, size = 1048560, size_out = 3016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00270_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, type = size, size_out = 3780 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, size = 1048560, size_out = 3780 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3792 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00273_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, type = size, size_out = 812 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, size = 1048560, size_out = 812 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00296_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 6996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00524_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 9590 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 3768 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3776 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1330 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 7974 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7984 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 1712 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1728 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 3104 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3120 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2052 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2064 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 3524 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3536 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00441_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 3896 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3904 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00444_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7176 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7184 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10538 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10544 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2422 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2432 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 8256 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8272 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2832 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2848 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 37974 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 37984 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17584 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00405_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 42908 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00414_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 712 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00419_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1932 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1936 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00437_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2004 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2016 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01168_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2404 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2416 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01170_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2232 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01172_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1888 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1904 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01176_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2024 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8564 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8576 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 900 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01631_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4148 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01761_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1382 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1392 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00010_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2700 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2704 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00172_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6938 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6944 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00202_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 18194 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18208 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4074 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4080 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00361_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00369_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00382_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8424 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00382_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8432 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00382_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00382_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00382_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16396 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16400 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00419_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00419_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8926 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8928 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00544_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5260 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00544_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00544_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00544_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00564_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 896 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00564_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00564_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00564_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00779_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9010 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00779_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00779_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00779_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 42704 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01548_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10316 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01548_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10320 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01548_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01548_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01658_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17924 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01658_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17936 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01658_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01658_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01660_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 12958 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01660_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01660_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01660_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02068_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2488 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02068_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02068_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02068_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02071_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2188 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02071_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2192 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02071_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02071_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1268 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5000 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01080_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01080_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01329_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01329_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01329_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01329_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01759_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5414 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01759_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5424 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01759_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01759_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01875_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2616 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01875_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2624 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01875_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01875_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 26706 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01923_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01923_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\IN00957_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2944 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\IN00957_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\IN00957_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\IN00957_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086420.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9596 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086420.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086420.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086420.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 35346 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086428.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090027.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 21268 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090027.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090027.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090027.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090779.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1456 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090779.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1472 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090779.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090779.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0093905.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 42050 True 1
Fn
Data
For performance reasons, the remaining 151 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xd24
6364 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, type = size, size_out = 6004 True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log, size = 1048560, size_out = 6004 True 1
Fn
Data
File Write filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6016 True 1
Fn
Data
File Read filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 276 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\eula.rtf, type = size, size_out = 8876 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1032\eula.rtf, size = 1048560, size_out = 8876 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8880 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1040\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1032\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\eula.rtf, type = size, size_out = 3188 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1033\eula.rtf, size = 1048560, size_out = 3188 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3200 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1033\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1033\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\eula.rtf, type = size, size_out = 3702 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1035\eula.rtf, size = 1048560, size_out = 3702 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3712 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1035\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1035\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\eula.rtf, type = size, size_out = 3526 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1036\eula.rtf, size = 1048560, size_out = 3526 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3536 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1036\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1036\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, type = size, size_out = 82962 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, size = 1048560, size_out = 82962 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 82976 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1036\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1036\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\eula.rtf, type = size, size_out = 4254 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1038\eula.rtf, size = 1048560, size_out = 4254 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4256 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1038\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1038\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\LocalizedData.xml, type = size, size_out = 3643 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1040\eula.rtf, size = 1048560, size_out = 3643 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3648 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1040\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1040\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, type = size, size_out = 68226 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, size = 1048560, size_out = 68226 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 68240 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1041\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1041\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\eula.rtf, type = size, size_out = 12687 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1042\eula.rtf, size = 1048560, size_out = 12687 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12688 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1042\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1042\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\eula.rtf, type = size, size_out = 3046 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1044\eula.rtf, size = 1048560, size_out = 3046 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3056 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1044\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1044\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, type = size, size_out = 79296 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, size = 1048560, size_out = 79296 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 79312 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1044\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1044\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, type = size, size_out = 82374 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, size = 1048560, size_out = 82374 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 82384 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1045\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1045\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, type = size, size_out = 80738 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, size = 1048560, size_out = 80738 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80752 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1046\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1046\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, type = size, size_out = 81482 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, size = 1048560, size_out = 81482 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 81488 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1049\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1049\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\eula.rtf, type = size, size_out = 3859 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1055\eula.rtf, size = 1048560, size_out = 3859 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3872 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1055\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1055\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 80254 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, size = 1048560, size_out = 80254 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80256 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2070\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, type = size, size_out = 60816 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, size = 1048560, size_out = 60816 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 60832 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\3076\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3076\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\UiInfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\UiInfo.xml, type = size, size_out = 39042 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\UiInfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\UiInfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Client\UiInfo.xml, size = 1048560, size_out = 39042 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 39056 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\header.bmp, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Client\UiInfo.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\ParameterInfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.xsd, type = size, size_out = 272046 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\ParameterInfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\ParameterInfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\ParameterInfo.xml, size = 1048560, size_out = 272046 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 272048 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\ParameterInfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\ParameterInfo.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\UiInfo.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\UiInfo.xml, type = size, size_out = 38898 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\UiInfo.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\UiInfo.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\UiInfo.xml, size = 1048560, size_out = 38898 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 38912 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\UiInfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\UiInfo.xml True 1
Fn
File Create filename = C:\Boot\BCD.LOG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\BOOTSTAT.DAT, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, type = size, size_out = 65536 True 1
Fn
File Get Info filename = C:\Boot\BOOTSTAT.DAT, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\BOOTSTAT.DAT, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Boot\BOOTSTAT.DAT, size = 1048560, size_out = 65536 True 1
Fn
Data
File Write filename = C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 65552 True 1
Fn
Data
File Read filename = C:\Boot\BOOTSTAT.DAT, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Boot\BOOTSTAT.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Boot\BOOTSTAT.DAT True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, type = size, size_out = 4782 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, size = 1048560, size_out = 4782 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4784 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 260 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml, type = size, size_out = 1434 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad\auxbase.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert\insertbase.xml, type = size, size_out = 212 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\auxpad.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, type = size, size_out = 215 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, type = size, size_out = 903 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml, type = size, size_out = 693 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml, type = size, size_out = 3333 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read size = 1048560, size_out = 7805 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7808 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, type = size, size_out = 153 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, size = 1048560, size_out = 153 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\README.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 46 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\README.txt, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\README.txt, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\README.txt, size = 1048560, size_out = 46 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\README.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\README.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\README.txt True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, type = size, size_out = 63933 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, size = 1048560, size_out = 63933 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 63936 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 280 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, type = size, size_out = 145180 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, size = 1048560, size_out = 145180 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 145184 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[idecryptyourdata@cock.li].bat, size = 266 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\SLERROR.XML, type = size, size_out = 94467 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS, size = 1048560, size_out = 94467 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat, size = 94480 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\Office16\OSPP.VBS True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, type = size, size_out = 1533 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1533 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1536 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, type = size, size_out = 800867 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 800867 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, size = 800880 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, type = size, size_out = 2147 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, size = 1048560, size_out = 2147 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, type = size, size_out = 2147 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, size = 1048560, size_out = 2147 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml, type = size, size_out = 65002 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 65002 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 65008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, type = size, size_out = 9216 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 9216 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9232 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, type = size, size_out = 3375 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 3375 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3376 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, type = size, size_out = 9831 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, size = 1048560, size_out = 9831 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9840 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, type = size, size_out = 9024 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, size = 1048560, size_out = 9024 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9040 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, type = size, size_out = 14873 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, size = 1048560, size_out = 14873 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14880 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, type = size, size_out = 6684 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, size = 1048560, size_out = 6684 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6688 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, type = size, size_out = 8097 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, size = 1048560, size_out = 8097 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8112 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, type = size, size_out = 517 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, size = 1048560, size_out = 517 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 528 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, type = size, size_out = 502 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, size = 1048560, size_out = 502 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 512 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00092_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, type = size, size_out = 12702 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, size = 1048560, size_out = 12702 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12704 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, type = size, size_out = 3484 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, size = 1048560, size_out = 3484 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3488 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF, type = size, size_out = 10607 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF, size = 1048560, size_out = 10607 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10608 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00139_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, type = size, size_out = 5030 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, size = 1048560, size_out = 5030 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5040 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00158_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF, type = size, size_out = 6984 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF, size = 1048560, size_out = 6984 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6992 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00169_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00163_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, type = size, size_out = 9248 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, size = 1048560, size_out = 9248 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, type = size, size_out = 4390 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, size = 1048560, size_out = 4390 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4400 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, type = size, size_out = 3966 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, size = 1048560, size_out = 3966 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, type = size, size_out = 3026 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, size = 1048560, size_out = 3026 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3040 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00010_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, size = 1048560, size_out = 5684 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5696 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00790_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, size = 1048560, size_out = 10832 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10848 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00015_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00914_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 1596 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 3746 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3760 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01184_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 5836 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5840 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 7372 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7376 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 6632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 9240 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9248 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 6060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6064 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 6636 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 4612 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4624 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04195_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, size = 1048560, size_out = 3144 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3152 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04206_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04196_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, size = 1048560, size_out = 2016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04269_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04225_.WMF, size = 1048560, size_out = 4296 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4304 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04369_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04332_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, size = 1048560, size_out = 4870 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4880 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 17236 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17248 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD05119_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 16676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16688 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00160_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06200_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 26748 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26752 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07761_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 4066 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4080 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD07831_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 24778 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24784 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08773_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 47996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD06102_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 47786 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 47792 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 14540 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 20554 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 7966 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 13515 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13520 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 20189 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20192 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 12520 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12528 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 9818 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9824 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 7862 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7872 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 10146 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1516 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1520 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 8070 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8080 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00195_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 1536 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00248_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 12482 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00261_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 5752 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5760 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00265_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 4164 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4176 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 27050 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27056 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00274_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00392_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 27552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27568 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1444 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 4976 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4992 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1588 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00224_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 1212 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00438_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2488 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00440_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2436 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2448 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00442_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00453_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3494 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3504 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 3948 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3952 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2262 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2272 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 2690 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2704 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 40030 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 40032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 42992 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 43008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00413_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2952 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00448_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 20784 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2226 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3692 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3696 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1448 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF True 1
Fn
For performance reasons, the remaining 393 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xcf4
5819 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 42674 True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log, size = 1048560, size_out = 42674 True 1
Fn
Data
File Write filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42688 True 1
Fn
Data
File Read filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[idecryptyourdata@cock.li].bat, size = 286 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\eula.rtf, type = size, size_out = 6309 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1028\eula.rtf, size = 1048560, size_out = 6309 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6320 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1028\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1028\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, type = size, size_out = 60816 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, size = 1048560, size_out = 60816 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 60832 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1028\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1028\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\eula.rtf, type = size, size_out = 3726 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1029\eula.rtf, size = 1048560, size_out = 3726 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3728 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1029\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1029\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, type = size, size_out = 82346 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, size = 1048560, size_out = 82346 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 82352 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1031\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1031\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, type = size, size_out = 3683 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1046\eula.rtf, size = 1048560, size_out = 3683 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3696 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1046\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1046\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\eula.rtf, type = size, size_out = 5827 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2052\eula.rtf, size = 1048560, size_out = 5827 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5840 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2052\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2052\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, type = size, size_out = 60684 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, size = 1048560, size_out = 60684 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 60688 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2052\LocalizedData.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2052\LocalizedData.xml True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\eula.rtf, type = size, size_out = 6309 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3076\eula.rtf, size = 1048560, size_out = 6309 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6320 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\3076\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3076\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\eula.rtf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\eula.rtf, type = size, size_out = 3069 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\eula.rtf, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\eula.rtf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3082\eula.rtf, size = 1048560, size_out = 3069 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3072 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Client\UiInfo.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3082\eula.rtf True 1
Fn
File Create filename = C:\588bce7c90097ed212\DHtmlHeader.html, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DHtmlHeader.html, type = size, size_out = 16118 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DHtmlHeader.html, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\DHtmlHeader.html, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\DHtmlHeader.html, size = 1048560, size_out = 16118 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16128 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\DHtmlHeader.html, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\DHtmlHeader.html True 1
Fn
File Create filename = C:\588bce7c90097ed212\SplashScreen.bmp, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SplashScreen.bmp, type = size, size_out = 41080 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SplashScreen.bmp, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\SplashScreen.bmp, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\SplashScreen.bmp, size = 1048560, size_out = 41080 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 41088 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\SplashScreen.bmp, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\SplashScreen.bmp True 1
Fn
File Create filename = C:\588bce7c90097ed212\watermark.bmp, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\watermark.bmp, type = size, size_out = 104072 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\watermark.bmp, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\watermark.bmp, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\watermark.bmp, size = 1048560, size_out = 104072 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 104080 True 1
Fn
Data
File Read filename = C:\Boot\updaterevokesipolicy.p7b, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\watermark.bmp True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = size, size_out = 791421 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, type = size, size_out = 111320 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, type = size, size_out = 2418 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml, type = size, size_out = 2616 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml, type = size, size_out = 2658 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsfin.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml, type = size, size_out = 2596 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrl.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm, type = size, size_out = 231 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.htm, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, type = size, size_out = 23871 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Garden.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg, type = size, size_out = 6406 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\GreenBubbles.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, size = 1048560, size_out = 14156 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, type = size, size_out = 153 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, size = 1048560, size_out = 153 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif, type = size, size_out = 147 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, size = 1048560, size_out = 147 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, type = size, size_out = 105500 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, size = 1048560, size_out = 105500 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat, size = 105504 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, type = size, size_out = 174528 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, size = 1048560, size_out = 174528 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, size = 174544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\Office16\OSPP.HTM True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, type = size, size_out = 19451 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 19451 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, type = size, size_out = 763363 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 763363 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 763376 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml, type = size, size_out = 14913 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 14913 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14928 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, type = size, size_out = 1450 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 1450 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, type = size, size_out = 3754 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 3754 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3760 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, type = size, size_out = 1261 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 1261 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, type = size, size_out = 373 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, size = 1048560, size_out = 373 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 384 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF, type = size, size_out = 7216 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF, size = 1048560, size_out = 7216 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7232 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00011_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 3251 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF, size = 1048560, size_out = 3251 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, type = size, size_out = 7686 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, size = 1048560, size_out = 7686 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7696 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, type = size, size_out = 11891 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, size = 1048560, size_out = 11891 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11904 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00057_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, type = size, size_out = 12482 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, size = 1048560, size_out = 12482 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, type = size, size_out = 5253 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, size = 1048560, size_out = 5253 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, type = size, size_out = 2596 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, size = 1048560, size_out = 2596 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2608 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, type = size, size_out = 5315 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, size = 1048560, size_out = 5315 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5328 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00154_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, type = size, size_out = 1146 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, size = 1048560, size_out = 1146 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1152 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, type = size, size_out = 7583 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, size = 1048560, size_out = 7583 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7584 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00161_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, type = size, size_out = 8582 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, size = 1048560, size_out = 8582 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8592 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00165_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, type = size, size_out = 4894 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, size = 1048560, size_out = 4894 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4896 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00167_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, type = size, size_out = 5016 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, size = 1048560, size_out = 5016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, type = size, size_out = 3378 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, size = 1048560, size_out = 3378 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3392 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, type = size, size_out = 20578 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, size = 1048560, size_out = 20578 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20592 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00853_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, type = size, size_out = 7072 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 7072 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7088 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN00965_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 7968 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF, size = 1048560, size_out = 7968 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7984 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01060_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, type = size, size_out = 26332 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, size = 1048560, size_out = 26332 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26336 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01173_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, type = size, size_out = 2756 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 2756 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2768 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 9710 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9712 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 8772 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8784 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 14486 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 18304 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18320 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 1012 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 1464 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1472 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 3986 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9304 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00234_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14444 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14448 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00247_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 19476 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19488 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 29004 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2378 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2384 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2166 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2176 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8366 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8368 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3564 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3568 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2262 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2272 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 29628 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29632 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 792 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00372_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7828 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7840 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00407_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9992 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00449_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24588 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24592 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14820 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14832 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3616 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3632 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2140 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2780 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2784 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2796 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2960 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3588 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2228 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01160_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2304 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01163_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2324 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2336 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00121_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 19068 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19072 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3252 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3264 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01793_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13042 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13056 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ED00019_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13936 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13952 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00006_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6780 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6784 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2280 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2288 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 736 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 752 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17308 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7944 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7952 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17850 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17856 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 30240 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 29212 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00090_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14194 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00090_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14208 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00090_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00090_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00403_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7878 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00403_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7888 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00403_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00403_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11002 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00414_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00414_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5098 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5104 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00438_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00775_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11152 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00775_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11168 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00775_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00775_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00799_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13968 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00799_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13984 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00799_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00799_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4634 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01074_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01074_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4984 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4992 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00586_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01176_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01176_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01193_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1160 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01193_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1168 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01193_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01193_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01659_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 31180 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01659_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31184 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01659_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01659_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02115_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4660 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02115_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4672 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02115_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02115_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02153_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5392 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02153_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5408 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02153_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02153_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02161_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3128 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02161_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3136 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02161_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02161_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FLAP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2070 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FLAP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2080 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FLAP.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FLAP.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1026 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1040 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00235_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00235_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3662 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3664 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00297_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1528 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1536 True 1
Fn
Data
For performance reasons, the remaining 267 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xa98
249 0
»
Category Operation Information Success Count Logfile
Thread 0xd44
2476 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, type = size, size_out = 144072 True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, size = 1048560, size_out = 144072 True 1
Fn
Data
File Write filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 144080 True 1
Fn
Data
File Read filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1035\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1035\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1035\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1049\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1049\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1049\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\SetupResources.dll, type = size, size_out = 17752 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1053\SetupResources.dll, size = 1048560, size_out = 17752 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17760 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1053\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1053\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\SetupResources.dll, type = size, size_out = 17752 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1055\SetupResources.dll, size = 1048560, size_out = 17752 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17760 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1055\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1055\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate7.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2070\LocalizedData.xml, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate8.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Save.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Save.ico, type = size, size_out = 1150 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Save.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Save.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Save.ico, size = 1048560, size_out = 1150 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1152 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Save.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Save.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Setup.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Setup.ico, type = size, size_out = 36710 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Setup.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Setup.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Setup.ico, size = 1048560, size_out = 36710 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36720 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Setup.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Setup.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\warn.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\warn.ico, type = size, size_out = 10134 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\warn.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\warn.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\warn.ico, size = 1048560, size_out = 10134 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10144 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\warn.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\warn.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, type = size, size_out = 1163264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, size = 1048560, size_out = 114704 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 114720 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\netfx_Core_x86.msi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\netfx_Core_x86.msi True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml, type = size, size_out = 872448 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, size = 1048560, size_out = 872448 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 872464 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\netfx_Extended_x64.msi True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, type = size, size_out = 495616 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, size = 1048560, size_out = 495616 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 495632 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\netfx_Extended_x86.msi True 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, type = size, size_out = 184832 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, size = 1048560, size_out = 184832 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 184848 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\RGB9RAST_x64.msi True 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, type = size, size_out = 94720 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, size = 1048560, size_out = 94720 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 94736 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\RGB9Rast_x86.msi True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.dll, type = size, size_out = 295248 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\SetupUi.dll, size = 1048560, size_out = 295248 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 295264 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\SetupUi.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\SetupUi.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUtility.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUtility.exe, type = size, size_out = 96088 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUtility.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUtility.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\SetupUtility.exe, size = 1048560, size_out = 96088 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 96096 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\SetupUtility.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\SetupUtility.exe True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu, type = size, size_out = 5198099 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu, destination_filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786734 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Boot\BCD, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\BCD.LOG1, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG1, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\BCD.LOG2, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG2, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = size, size_out = 77664 True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = size, size_out = 95648 True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = size, size_out = 99744 True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Boot\Fonts\chs_boot.ttf, destination_filename = C:\Boot\Fonts\chs_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\cht_boot.ttf, destination_filename = C:\Boot\Fonts\cht_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\jpn_boot.ttf, destination_filename = C:\Boot\Fonts\jpn_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\kor_boot.ttf, destination_filename = C:\Boot\Fonts\kor_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\bootmgr, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1 True 1
Fn
Data
File Write filename = C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\BOOTNXT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\BOOTNXT True 1
Fn
File Create filename = C:\hiberfil.sys, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Logs\Application.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Application.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Application.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Application.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Application.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Application.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Application.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Logs\Application.evtx True 1
Fn
File Create filename = C:\Logs\HardwareEvents.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\HardwareEvents.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\HardwareEvents.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\HardwareEvents.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\HardwareEvents.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\HardwareEvents.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\HardwareEvents.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Logs\HardwareEvents.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 324 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 304 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 322 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 340 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 368 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Known Folders API Service.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-MUI%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, size = 290 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-MUI%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 304 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 304 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 302 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 356 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx True 1
Fn
File Create filename = C:\Logs\Windows PowerShell.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Windows PowerShell.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Windows PowerShell.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Windows PowerShell.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Windows PowerShell.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Windows PowerShell.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Windows PowerShell.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Windows PowerShell.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Windows PowerShell.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Windows PowerShell.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Logs\Windows PowerShell.evtx True 1
Fn
File Create filename = C:\pagefile.sys, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, type = size, size_out = 15984 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, size = 1048560, size_out = 15984 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16000 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 19136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll, size = 1048560, size_out = 19136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19152 False 1
Fn
Thread 0x58
2424 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, type = size, size_out = 577 True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd, size = 1048560, size_out = 577 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1025\SetupResources.dll, size = 592 True 1
Fn
Data
File Read filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1025\SetupResources.dll, size = 260 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\GetCurrentRollback.ini, type = size, size_out = 14168 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1028\SetupResources.dll, size = 1048560, size_out = 14168 True 1
Fn
Data
File Write filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, size = 14176 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1028\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1030\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1030\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1030\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\SetupResources.dll, type = size, size_out = 15704 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1041\SetupResources.dll, size = 1048560, size_out = 15704 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15712 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1041\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1041\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\SetupResources.dll, type = size, size_out = 15192 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1042\SetupResources.dll, size = 1048560, size_out = 15192 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15200 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1033\eula.rtf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1042\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 19288 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1043\SetupResources.dll, size = 1048560, size_out = 19288 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19296 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1043\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1043\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\SetupResources.dll, type = size, size_out = 18776 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3082\SetupResources.dll, size = 1048560, size_out = 18776 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18784 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\3082\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3082\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\DisplayIcon.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DisplayIcon.ico, type = size, size_out = 88533 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DisplayIcon.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\DisplayIcon.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\DisplayIcon.ico, size = 1048560, size_out = 88533 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 88544 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\DisplayIcon.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\DisplayIcon.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Print.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 1150 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Print.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Print.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Print.ico, size = 1048560, size_out = 1150 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1152 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Print.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Print.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate4.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate5.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate6.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, type = size, size_out = 1150 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, size = 1048560, size_out = 1150 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1152 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\SysReqMet.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core_x64.msi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x64.msi, type = size, size_out = 1901056 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x64.msi, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\netfx_Core_x64.msi, destination_filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786704 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\588bce7c90097ed212\Setup.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Setup.exe, type = size, size_out = 78152 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Setup.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Setup.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Setup.exe, size = 1048560, size_out = 78152 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 78160 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Setup.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Setup.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Setup.exe True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupEngine.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupEngine.dll, type = size, size_out = 807256 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupEngine.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupEngine.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\SetupEngine.dll, size = 1048560, size_out = 807256 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 807264 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\SetupEngine.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\SetupEngine.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\sqmapi.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\sqmapi.dll, type = size, size_out = 144416 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\sqmapi.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\sqmapi.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\sqmapi.dll, size = 1048560, size_out = 144416 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 144432 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\sqmapi.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\sqmapi.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu, type = size, size_out = 5091790 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu, destination_filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786734 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 368 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 354 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, type = size, size_out = 1118208 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, size = 1048560, size_out = 69648 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69664 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 338 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 320 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 314 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 290 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 304 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 302 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 352 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 364 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 324 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 316 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 300 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 376 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx True 1
Fn
File Create filename = C:\Logs\Setup.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Setup.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Setup.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Setup.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Setup.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Setup.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Setup.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Setup.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Setup.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Setup.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Logs\Setup.evtx True 1
Fn
File Create filename = C:\Logs\System.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\System.evtx, type = size, size_out = 1118208 True 1
Fn
File Get Info filename = C:\Logs\System.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\System.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\System.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\System.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\System.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\System.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\System.evtx, size = 1048560, size_out = 69648 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, size = 69664 True 1
Fn
Data
File Read filename = C:\Logs\System.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB, size = 234 True 1
Fn
Data
File Delete filename = C:\Logs\System.evtx True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, type = size, size_out = 21184 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, size = 1048560, size_out = 21184 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21200 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 290 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll, type = size, size_out = 19136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll, size = 1048560, size_out = 19136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19152 False 1
Fn
Thread 0x2e8
2067 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\$GetCurrent\SafeOS\preoobe.cmd, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 74 True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\preoobe.cmd, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\preoobe.cmd, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\SafeOS\preoobe.cmd, size = 1048560, size_out = 74 True 1
Fn
Data
File Write filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80 True 1
Fn
Data
File Read filename = C:\$GetCurrent\SafeOS\preoobe.cmd, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\SafeOS\preoobe.cmd True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\SetupResources.dll, type = size, size_out = 18776 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1031\SetupResources.dll, size = 1048560, size_out = 18776 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18784 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1031\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1031\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\SetupResources.dll, type = size, size_out = 19288 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1032\SetupResources.dll, size = 1048560, size_out = 19288 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19296 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1032\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1032\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\SetupResources.dll, type = size, size_out = 17240 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1033\SetupResources.dll, size = 1048560, size_out = 17240 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1040\SetupResources.dll, size = 17248 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1033\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1040\SetupResources.dll, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1033\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\SetupResources.dll, type = size, size_out = 17752 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1044\SetupResources.dll, size = 1048560, size_out = 17752 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17760 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1044\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1044\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1045\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1045\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1045\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1046\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Print.ico, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1046\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Print.ico, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1046\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate1.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate2.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, type = size, size_out = 894 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, size = 1048560, size_out = 894 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 896 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\Rotate3.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core.mzz, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core.mzz, type = size, size_out = 181483595 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core.mzz, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\netfx_Core.mzz, destination_filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786696 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu, type = size, size_out = 2192672 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu, destination_filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786734 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu, type = size, size_out = 2141433 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu, destination_filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786734 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Logs\Internet Explorer.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Internet Explorer.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Internet Explorer.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Internet Explorer.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Internet Explorer.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Internet Explorer.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Internet Explorer.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Logs\Internet Explorer.evtx True 1
Fn
File Create filename = C:\Logs\Key Management Service.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Key Management Service.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Key Management Service.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Key Management Service.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Key Management Service.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Key Management Service.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Key Management Service.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 266 True 1
Fn
Data
File Delete filename = C:\Logs\Key Management Service.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 302 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 326 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 312 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx, type = size, size_out = 2166784 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx, destination_filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786780 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-International%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 306 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 360 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 304 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 340 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 294 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 294 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Store%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 344 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 356 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 326 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 300 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, type = size, size_out = 1052672 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, size = 1048560, size_out = 4112 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 308 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, type = size, size_out = 19136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, size = 1048560, size_out = 19136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19152 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 276 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, type = size, size_out = 18624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, size = 1048560, size_out = 18624 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18640 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 282 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, type = size, size_out = 11616 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, size = 1048560, size_out = 11616 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11632 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, type = size, size_out = 19648 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, size = 1048560, size_out = 19648 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19664 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, type = size, size_out = 22720 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, size = 1048560, size_out = 22720 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 22736 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll, type = size, size_out = 19648 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll, size = 1048560, size_out = 19648 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19664 False 1
Fn
Thread 0xa34
1641 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x75e90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x75ea6b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, type = size, size_out = 307 True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, type = file_attributes True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, size = 1048560, size_out = 307 True 1
Fn
Data
File Write filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 320 True 1
Fn
Data
File Read filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\$GetCurrent\SafeOS\SetupComplete.cmd True 1
Fn
File Create filename = C:\$WINRE_BACKUP_PARTITION.MARKER, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 0 True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\SetupResources.dll, type = size, size_out = 17240 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1025\SetupResources.dll, size = 1048560, size_out = 17240 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17248 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1025\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1025\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\SetupResources.dll, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1029\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1029\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\SetupResources.dll, type = size, size_out = 18776 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1036\SetupResources.dll, size = 1048560, size_out = 18776 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18784 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1036\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1036\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\SetupResources.dll, type = size, size_out = 16728 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1037\SetupResources.dll, size = 1048560, size_out = 16728 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16736 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1037\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1037\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\SetupResources.dll, type = size, size_out = 18776 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1038\SetupResources.dll, size = 1048560, size_out = 18776 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18784 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1038\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1038\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 18264 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\1040\SetupResources.dll, size = 1048560, size_out = 18264 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18272 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\1040\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\1040\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\SetupResources.dll, type = size, size_out = 14168 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2052\SetupResources.dll, size = 1048560, size_out = 14168 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14176 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2052\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2052\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\SetupResources.dll, type = size, size_out = 18776 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\2070\SetupResources.dll, size = 1048560, size_out = 18776 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18784 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\2070\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\2070\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\SetupResources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\SetupResources.dll, type = size, size_out = 14168 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\SetupResources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\SetupResources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\3076\SetupResources.dll, size = 1048560, size_out = 14168 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14176 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\3076\SetupResources.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\3076\SetupResources.dll True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\stop.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\stop.ico, type = size, size_out = 10134 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\stop.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\stop.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\stop.ico, size = 1048560, size_out = 10134 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10144 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\stop.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\stop.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, type = size, size_out = 1150 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, size = 1048560, size_out = 1150 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1152 True 1
Fn
Data
File Read filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended.mzz, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended.mzz, type = size, size_out = 43131591 True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended.mzz, type = file_attributes True 1
Fn
File Get Info filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\588bce7c90097ed212\netfx_Extended.mzz, destination_filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786704 True 1
Fn
Data
File Write filename = C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 294 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 298 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 310 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 330 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 324 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 318 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 314 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 292 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 312 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 292 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 276 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 300 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 302 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 326 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, size = 1048560, size_out = 69632 True 1
Fn
Data
File Write filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69648 True 1
Fn
Data
File Read filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296 True 1
Fn
Data
File Delete filename = C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx True 1
Fn
File Create filename = C:\Logs\Security.evtx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Logs\Security.evtx, type = size, size_out = 1118208 True 1
Fn
File Get Info filename = C:\Logs\Security.evtx, type = file_attributes True 1
Fn
File Get Info filename = C:\Logs\Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Logs\Security.evtx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Logs\Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Logs\Security.evtx, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Logs\Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Logs\Security.evtx, size = 1048560, size_out = 69648 True 1
Fn
Data
File Write filename = C:\Logs\Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69664 True 1
Fn
Data
File Read filename = C:\Logs\Security.evtx, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Logs\Security.evtx.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Logs\Security.evtx True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, type = size, size_out = 18624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, size = 1048560, size_out = 18624 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18640 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, type = size, size_out = 18624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, size = 1048560, size_out = 18624 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18640 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll, type = size, size_out = 20672 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll, size = 1048560, size_out = 20672 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20688 False 1
Fn
Thread 0xd9c
498 0
»
Category Operation Information Success Count Logfile
Process #2: cmd.exe
143 0
»
Information Value
ID #2
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:01:14, Reason: Self Terminated
Monitor Duration 00:00:31
OS Process Information
»
Information Value
PID 0xf8c
Parent PID 0xe0c (c:\users\fd1hvy\desktop\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F64
0x 4D0
0x 2AC
Threads
Thread 0xf64
143 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x7ff6b42a0000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x7ff92fdea990 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\FD1HVy\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\FD1HVy\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
System Get Info type = Operating System True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 38 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 52 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff92fdd0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7ff92fdee830 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x7ff92fdee300 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x7ff92f1b0a40 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 24 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 24 True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\WINDOWS\system32\mode.com, os_pid = 0x83c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Load module_name = NTDLL.DLL, base_address = 0x7ff931f40000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ntdll.dll, function = NtQueryInformationProcess, address_out = 0x7ff931fe56b0 True 1
Fn
Process Get Info type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory Read process_name = C:\WINDOWS\system32\mode.com, address = 947687292928, size = 1952 True 1
Fn
Data
Process #4: mode.com
0 0
»
Information Value
ID #4
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\Users\FD1HVy\Desktop\
Monitor Start Time: 00:01:11, Reason: Child Process
Unmonitor End Time: 00:03:22, Reason: Terminated by Timeout
Monitor Duration 00:02:10
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x83c
Parent PID 0xf8c (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x A70
0x A80
0x AEC
Process #5: hgaibc.exe
13731 0
»
Information Value
ID #5
File Name c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:29, Reason: Autostart
Unmonitor End Time: 00:03:04, Reason: Self Terminated
Monitor Duration 00:00:34
OS Process Information
»
Information Value
PID 0xe24
Parent PID 0x9d4 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E28
0x E2C
0x E48
0x E4C
0x E50
0x E54
0x E58
0x E60
0x E74
0x E78
0x E7C
0x E80
0x E84
0x E88
0x E8C
0x E90
0x E94
0x E98
0x EB4
0x EBC
0x EC4
0x ECC
0x ED0
0x ED4
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Relevant Image - 32-bit - False False
hgaibc.exe 0x00400000 0x00418FFF Process Termination - 32-bit - False False
Threads
Thread 0xe28
385 0
»
Category Operation Information Success Count Logfile
Module Load module_name = kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x770bed70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x77066760 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x770bf090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersion, address_out = 0x770656c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x770646b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x770bf180 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x770657f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreatePipe, address_out = 0x77064590 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringW, address_out = 0x77064430 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringA, address_out = 0x77064410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x77065010 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Module Load module_name = advapi32.dll, base_address = 0x75b90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Module Load module_name = user32.dll, base_address = 0x774c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Module Load module_name = Shell32.dll, base_address = 0x744f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Module Load module_name = ntdll.dll, base_address = 0x77850000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Module Load module_name = mpr.dll, base_address = 0x74250000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Module Load module_name = ws2_32.dll, base_address = 0x76f10000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = socket, address_out = 0x76f24510 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = send, address_out = 0x76f15030 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = recv, address_out = 0x76f20c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = connect, address_out = 0x76f15410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = closesocket, address_out = 0x76f20910 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = inet_addr, address_out = 0x76f29160 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = ntohl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htonl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htons, address_out = 0x76f28ff0 True 1
Fn
System Get Time type = Performance Ctr, time = 7330864441 True 1
Fn
System Get Time type = Ticks, time = 73265 True 3
Fn
System Get Info type = Operating System True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE False 1
Fn
Mutex Create mutex_name = Global\syncronize_1TPBM0A True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE False 1
Fn
Mutex Create mutex_name = Global\syncronize_1TPBM0U True 1
Fn
System Get Info type = Operating System True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\WINDOWS\System32\hgaibc.exe, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\Users\FD1HVy\AppData\Roaming\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run True 1
Fn
Registry Write Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, value_name = hgaibc.exe, data = 7237488, size = 84, type = REG_SZ False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, value_name = hgaibc.exe, data = C:\Users\FD1HVy\AppData\Roaming\hgaibc.exe, size = 84, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
Process Create process_name = C:\WINDOWS\system32\cmd.exe, os_pid = 0xe40, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Write size = 65 True 1
Fn
Data
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
Process Create process_name = C:\WINDOWS\system32\cmd.exe, os_pid = 0xbb0, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Write size = 65 True 1
Fn
Data
Thread 0xe48
3583 0
»
Category Operation Information Success Count Logfile
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
For performance reasons, the remaining 192 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xe4c
13 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
Process Create process_name = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, show_window = SW_SHOWNORMAL True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Mutex Release mutex_name = Global\syncronize_1TPBM0A True 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Thread 0xe50
31 0
»
Category Operation Information Success Count Logfile
System Get Computer Name result_out = NQDPDE True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 32
Fn
Thread 0xe54
107 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 75531 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Get Time type = Ticks, time = 75703 True 1
Fn
System Get Time type = Ticks, time = 76078 True 1
Fn
System Get Time type = Ticks, time = 76671 True 2
Fn
System Get Time type = Ticks, time = 77343 True 1
Fn
System Get Time type = Ticks, time = 77734 True 2
Fn
System Get Time type = Ticks, time = 77953 True 1
Fn
System Get Time type = Ticks, time = 78406 True 1
Fn
System Get Time type = Ticks, time = 78828 True 2
Fn
System Get Time type = Ticks, time = 79078 True 1
Fn
System Get Time type = Ticks, time = 79406 True 1
Fn
System Get Time type = Ticks, time = 79781 True 1
Fn
System Get Time type = Ticks, time = 80109 True 2
Fn
System Get Time type = Ticks, time = 80656 True 1
Fn
System Get Time type = Ticks, time = 80984 True 1
Fn
System Get Time type = Ticks, time = 81296 True 2
Fn
System Get Time type = Ticks, time = 81562 True 1
Fn
System Get Time type = Ticks, time = 81812 True 1
Fn
System Get Time type = Ticks, time = 81968 True 1
Fn
System Get Time type = Ticks, time = 82218 True 1
Fn
System Get Time type = Ticks, time = 82468 True 2
Fn
System Get Time type = Ticks, time = 82734 True 1
Fn
System Get Time type = Ticks, time = 82937 True 1
Fn
System Get Time type = Ticks, time = 83250 True 1
Fn
System Get Time type = Ticks, time = 83515 True 2
Fn
System Get Time type = Ticks, time = 83937 True 1
Fn
System Get Time type = Ticks, time = 84265 True 1
Fn
System Get Time type = Ticks, time = 84656 True 2
Fn
System Get Time type = Ticks, time = 85125 True 1
Fn
System Get Time type = Ticks, time = 85390 True 1
Fn
System Get Time type = Ticks, time = 85562 True 1
Fn
System Get Time type = Ticks, time = 85828 True 2
Fn
System Get Time type = Ticks, time = 86203 True 1
Fn
System Get Time type = Ticks, time = 86500 True 1
Fn
System Get Time type = Ticks, time = 86734 True 1
Fn
System Get Time type = Ticks, time = 87234 True 2
Fn
System Get Time type = Ticks, time = 87531 True 1
Fn
System Get Time type = Ticks, time = 87718 True 1
Fn
System Get Time type = Ticks, time = 88062 True 1
Fn
System Get Time type = Ticks, time = 88265 True 2
Fn
System Get Time type = Ticks, time = 88437 True 1
Fn
System Get Time type = Ticks, time = 88750 True 1
Fn
System Get Time type = Ticks, time = 89328 True 2
Fn
System Get Time type = Ticks, time = 90078 True 1
Fn
System Get Time type = Ticks, time = 90515 True 2
Fn
System Get Time type = Ticks, time = 90781 True 1
Fn
System Get Time type = Ticks, time = 91078 True 1
Fn
System Get Time type = Ticks, time = 91343 True 1
Fn
System Get Time type = Ticks, time = 91593 True 2
Fn
System Get Time type = Ticks, time = 91734 True 1
Fn
System Get Time type = Ticks, time = 91937 True 1
Fn
System Get Time type = Ticks, time = 92203 True 1
Fn
System Get Time type = Ticks, time = 92656 True 2
Fn
System Get Time type = Ticks, time = 92875 True 1
Fn
System Get Time type = Ticks, time = 93093 True 1
Fn
System Get Time type = Ticks, time = 93296 True 1
Fn
System Get Time type = Ticks, time = 93562 True 1
Fn
System Get Time type = Ticks, time = 93765 True 2
Fn
System Get Time type = Ticks, time = 93937 True 1
Fn
System Get Time type = Ticks, time = 94390 True 1
Fn
System Get Time type = Ticks, time = 94765 True 1
Fn
System Get Time type = Ticks, time = 95265 True 2
Fn
System Get Time type = Ticks, time = 95609 True 1
Fn
System Get Time type = Ticks, time = 95968 True 1
Fn
System Get Time type = Ticks, time = 96125 True 1
Fn
System Get Time type = Ticks, time = 96250 True 1
Fn
System Get Time type = Ticks, time = 96437 True 2
Fn
System Get Time type = Ticks, time = 96546 True 1
Fn
System Get Time type = Ticks, time = 96765 True 1
Fn
System Get Time type = Ticks, time = 96921 True 1
Fn
System Get Time type = Ticks, time = 97187 True 1
Fn
System Get Time type = Ticks, time = 97437 True 1
Fn
System Get Time type = Ticks, time = 97656 True 2
Fn
System Get Time type = Ticks, time = 97796 True 1
Fn
System Get Time type = Ticks, time = 97953 True 1
Fn
System Get Time type = Ticks, time = 98109 True 1
Fn
System Get Time type = Ticks, time = 98265 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe60
110 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 75500 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Get Time type = Ticks, time = 75703 True 1
Fn
System Get Time type = Ticks, time = 76078 True 1
Fn
System Get Time type = Ticks, time = 76671 True 2
Fn
System Get Time type = Ticks, time = 77343 True 1
Fn
System Get Time type = Ticks, time = 77734 True 2
Fn
System Get Time type = Ticks, time = 77953 True 1
Fn
System Get Time type = Ticks, time = 78421 True 1
Fn
System Get Time type = Ticks, time = 78828 True 2
Fn
System Get Time type = Ticks, time = 79078 True 1
Fn
System Get Time type = Ticks, time = 79406 True 1
Fn
System Get Time type = Ticks, time = 79781 True 1
Fn
System Get Time type = Ticks, time = 80109 True 2
Fn
System Get Time type = Ticks, time = 80656 True 1
Fn
System Get Time type = Ticks, time = 80984 True 1
Fn
System Get Time type = Ticks, time = 81296 True 2
Fn
System Get Time type = Ticks, time = 81546 True 1
Fn
System Get Time type = Ticks, time = 81812 True 1
Fn
System Get Time type = Ticks, time = 81968 True 1
Fn
System Get Time type = Ticks, time = 82218 True 1
Fn
System Get Time type = Ticks, time = 82468 True 2
Fn
System Get Time type = Ticks, time = 82734 True 1
Fn
System Get Time type = Ticks, time = 82937 True 1
Fn
System Get Time type = Ticks, time = 83250 True 1
Fn
System Get Time type = Ticks, time = 83515 True 2
Fn
System Get Time type = Ticks, time = 83937 True 1
Fn
System Get Time type = Ticks, time = 84265 True 1
Fn
System Get Time type = Ticks, time = 84656 True 2
Fn
System Get Time type = Ticks, time = 85125 True 1
Fn
System Get Time type = Ticks, time = 85390 True 1
Fn
System Get Time type = Ticks, time = 85562 True 1
Fn
System Get Time type = Ticks, time = 85828 True 2
Fn
System Get Time type = Ticks, time = 86203 True 1
Fn
System Get Time type = Ticks, time = 86500 True 1
Fn
System Get Time type = Ticks, time = 86734 True 1
Fn
System Get Time type = Ticks, time = 87234 True 2
Fn
System Get Time type = Ticks, time = 87531 True 1
Fn
System Get Time type = Ticks, time = 87718 True 1
Fn
System Get Time type = Ticks, time = 88062 True 1
Fn
System Get Time type = Ticks, time = 88265 True 2
Fn
System Get Time type = Ticks, time = 88437 True 1
Fn
System Get Time type = Ticks, time = 88750 True 1
Fn
System Get Time type = Ticks, time = 89328 True 2
Fn
System Get Time type = Ticks, time = 90078 True 1
Fn
System Get Time type = Ticks, time = 90515 True 2
Fn
System Get Time type = Ticks, time = 90781 True 1
Fn
System Get Time type = Ticks, time = 91078 True 1
Fn
System Get Time type = Ticks, time = 91343 True 1
Fn
System Get Time type = Ticks, time = 91593 True 2
Fn
System Get Time type = Ticks, time = 91734 True 1
Fn
System Get Time type = Ticks, time = 91937 True 1
Fn
System Get Time type = Ticks, time = 92203 True 1
Fn
System Get Time type = Ticks, time = 92656 True 2
Fn
System Get Time type = Ticks, time = 92875 True 1
Fn
System Get Time type = Ticks, time = 93093 True 1
Fn
System Get Time type = Ticks, time = 93296 True 1
Fn
System Get Time type = Ticks, time = 93562 True 1
Fn
System Get Time type = Ticks, time = 93765 True 2
Fn
System Get Time type = Ticks, time = 93937 True 1
Fn
System Get Time type = Ticks, time = 94390 True 1
Fn
System Get Time type = Ticks, time = 94765 True 1
Fn
System Get Time type = Ticks, time = 95265 True 2
Fn
System Get Time type = Ticks, time = 95609 True 1
Fn
System Get Time type = Ticks, time = 95968 True 1
Fn
System Get Time type = Ticks, time = 96125 True 1
Fn
System Get Time type = Ticks, time = 96250 True 1
Fn
System Get Time type = Ticks, time = 96437 True 2
Fn
System Get Time type = Ticks, time = 96546 True 1
Fn
System Get Time type = Ticks, time = 96765 True 1
Fn
System Get Time type = Ticks, time = 96921 True 1
Fn
System Get Time type = Ticks, time = 97187 True 1
Fn
System Get Time type = Ticks, time = 97437 True 1
Fn
System Get Time type = Ticks, time = 97656 True 2
Fn
System Get Time type = Ticks, time = 97796 True 1
Fn
System Get Time type = Ticks, time = 97953 True 1
Fn
System Get Time type = Ticks, time = 98109 True 1
Fn
System Get Time type = Ticks, time = 98265 True 1
Fn
System Get Time type = Ticks, time = 98453 True 1
Fn
System Get Time type = Ticks, time = 98734 True 2
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe74
753 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 4
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = size, size_out = 99744 True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\Fonts\jpn_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\jpn_boot.ttf, type = size, size_out = 1985867 True 1
Fn
File Get Info filename = C:\Boot\Fonts\jpn_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\jpn_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Boot\Fonts\jpn_boot.ttf, destination_filename = C:\Boot\Fonts\jpn_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Boot\Fonts\kor_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\kor_boot.ttf, type = size, size_out = 2373000 True 1
Fn
File Get Info filename = C:\Boot\Fonts\kor_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\kor_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Boot\Fonts\kor_boot.ttf, destination_filename = C:\Boot\Fonts\kor_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Boot\Fonts\malgunn_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgunn_boot.ttf, type = size, size_out = 174959 True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgunn_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgunn_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\Fonts\malgunn_boot.ttf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\Fonts\malgun_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgun_boot.ttf, type = size, size_out = 177414 True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgun_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\malgun_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\Fonts\malgun_boot.ttf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\Fonts\meiryon_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryon_boot.ttf, type = size, size_out = 143754 True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryon_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryon_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\Fonts\meiryon_boot.ttf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\Fonts\meiryo_boot.ttf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryo_boot.ttf, type = size, size_out = 145419 True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryo_boot.ttf, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\Fonts\meiryo_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\Fonts\meiryo_boot.ttf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\InkObj.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\InkObj.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\micaut.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\micaut.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\tabskb.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\tabskb.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_KMS_Automation-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365ProPlusR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms, type = size, size_out = 11601 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms, type = size, size_out = 590523 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms, type = size, size_out = 20779 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms, type = size, size_out = 11614 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms, type = size, size_out = 10655 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms, type = size, size_out = 20784 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdCO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessEntryR_PrepidBypass-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeServiceBypassR_PrepidBypass-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeServiceBypassR_PrepidBypass-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeServiceBypassR_PrepidBypass-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardMSDNR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardMSDNR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardMSDNR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_PostCommon.Office.x-none.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLLIBR.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLLIBR.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK.HOL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLOOK_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PE.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PIPELINE.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PJINTL.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PJINTL.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\POWERPNT.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\POWERPNT_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\POWERPNT_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\POWERPNT_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\POWERPNT_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROPRPT.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROPRPT.VSSX.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUB6INTL.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUB6INTL.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBCOLOR.SCM.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SAVASWEB.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SETLANG.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SETLANG_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SETLANG_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SETLANG_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SETLANG_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SHAPNUM.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_BASIC.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_BASIC_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_BASIC_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\DocumentFormat.OpenXml.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\DocumentFormat.OpenXml.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\MSSPC.ECF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\OUTEX.ECF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\OUTEX2.ECF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PMAILEXT.ECF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power Map Excel Add-in\MICROSOFT.DATA.RECOMMENDATION.CLIENT.CORE.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power Map Excel Add-in\MICROSOFT.DATA.RECOMMENDATION.CLIENT.CORE.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power Map Excel Add-in\VISUALIZATIONCONTROL.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power Map Excel Add-in\VISUALIZATIONCONTROL.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\hi\PowerViewRes.hi.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\hr\PowerViewRes.hr.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\hu\PowerViewRes.hu.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\id\PowerViewRes.id.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\it\PowerViewRes.it.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\lv\PowerViewRes.lv.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\Microsoft.Reporting.AdHoc.Shell.Bootstrapper.xap, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\Microsoft.Reporting.AdHoc.Shell.Bootstrapper.xap.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sr-cyrl\PowerViewRes.sr-cyrl.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sr-latn\PowerViewRes.sr-latn.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sr-Latn-CS\PowerViewRes.sr-Latn-CS.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sv\PowerViewRes.sv.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\th\PowerViewRes.th.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fi\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fi\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fr\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fr\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\gl\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\gl\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hu\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hu\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\id\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\id\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\it\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\it\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe78
1489 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$WINRE_BACKUP_PARTITION.MARKER, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$WINRE_BACKUP_PARTITION.MARKER, type = size, size_out = 0 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 3
Fn
File Create filename = C:\Boot\cs-CZ\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui, type = size, size_out = 76632 True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\cs-CZ\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\el-GR\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\el-GR\bootmgr.exe.mui, type = size, size_out = 80224 True 1
Fn
File Get Info filename = C:\Boot\el-GR\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\el-GR\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\el-GR\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\el-GR\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\el-GR\memtest.exe.mui, type = size, size_out = 46496 True 1
Fn
File Get Info filename = C:\Boot\el-GR\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\el-GR\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\el-GR\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\en-GB\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\en-GB\bootmgr.exe.mui, type = size, size_out = 74072 True 1
Fn
File Get Info filename = C:\Boot\en-GB\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\en-GB\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\en-GB\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\en-US\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\en-US\bootmgr.exe.mui, type = size, size_out = 74144 True 1
Fn
File Get Info filename = C:\Boot\en-US\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\en-US\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\en-US\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\en-US\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\en-US\memtest.exe.mui, type = size, size_out = 44960 True 1
Fn
File Get Info filename = C:\Boot\en-US\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\en-US\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\en-US\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\es-ES\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\es-ES\bootmgr.exe.mui, type = size, size_out = 77664 True 1
Fn
File Get Info filename = C:\Boot\es-ES\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\es-ES\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\es-ES\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\es-ES\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\es-ES\memtest.exe.mui, type = size, size_out = 45984 True 1
Fn
File Get Info filename = C:\Boot\es-ES\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\es-ES\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\es-ES\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\es-MX\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\es-MX\bootmgr.exe.mui, type = size, size_out = 77664 True 1
Fn
File Get Info filename = C:\Boot\es-MX\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\es-MX\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\es-MX\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\et-EE\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\et-EE\bootmgr.exe.mui, type = size, size_out = 75104 True 1
Fn
File Get Info filename = C:\Boot\et-EE\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\et-EE\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\et-EE\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\fi-FI\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\fi-FI\bootmgr.exe.mui, type = size, size_out = 76640 True 1
Fn
File Get Info filename = C:\Boot\fi-FI\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\fi-FI\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\fi-FI\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Boot\Fonts\cht_boot.ttf, destination_filename = C:\Boot\Fonts\cht_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\bootmgr, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui, type = size, size_out = 5120 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tabskb.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui, type = size, size_out = 25088 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\TipRes.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui, type = size, size_out = 9728 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\es-ES\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, type = size, size_out = 17920 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msader15.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll, type = size, size_out = 2560 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msader15.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado15.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll, type = size, size_out = 1233920 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado15.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_sv.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_CN.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_TW.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\cldrdata.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\cldrdata.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\jfxrt.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\jfxrt.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\localedata.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\localedata.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\nashorn.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\nashorn.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\sunmscapi.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\sunpkcs11.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\zipfs.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.bfc.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiItalic.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterBold.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterRegular.ttf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\hijrah-config-umalqura.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\javaws.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\java.policy.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\java.security.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\javaws.policy.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\local_policy.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\US_export_policy.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\sound.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\tzmappings.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\LICENSE.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\release.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\JNGLE_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NBOOK_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\OCEAN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\OUTDR_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PAPER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_03.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_04.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_05.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_06.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_07.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_08.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_09.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PARNT_10.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\ROAD_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SAFRI_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SCHOL_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SHOW_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SPACE_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SPRNG_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SUMER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SWEST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeStudentR_Trial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PersonalR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProMSDNR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProR_Retail2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PublisherVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessEntryR_PrepidBypass-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\WordVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DataServices\FOLDER.ICO.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DBWIZ.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DOORSCHD.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DRILLDWN.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DWGCNV.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EQPLIST.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXCEL.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXCEL_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXCEL_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXCEL_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXCEL_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\FACILITY.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\FLOCH.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GANTT.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GANTT.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GR8GALRY.GRA.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GRAPH_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GROOVE.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GROOVE_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GROOVE_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GROOVE_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GROOVE_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\HVAC.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\HVACDIFF.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\HVACDUCT.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\INSTLIST.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\INVENTRY.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LGND.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_BASIC.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_BASIC_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_BASIC_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_BASIC_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_BASIC_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_ONLINE.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_ONLINE_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_ONLINE_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_ONLINE_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\LYNC_ONLINE_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ORGWIZ.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_STD_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_STD_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINSCHD.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINWORD_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WORKFLOW.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\XFUNC.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\XLINTL32.DLL, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\XLINTL32.DLL.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1036\MSO.ACL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\3082\MSO.ACL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCICONS.EXE, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCICONS.EXE.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZDAT12.ACCDU, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZDAT12.ACCDU.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZUSR12.ACCDU, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZUSR12.ACCDU.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\FAXEXT.ECF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Document.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Document.resources.dll, type = size, size_out = 203432 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Document.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Document.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.Mashup.Document.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.MashupEngine.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.MashupEngine.resources.dll, type = size, size_out = 580264 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.MashupEngine.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.MashupEngine.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\nl\Microsoft.MashupEngine.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Excel.resources.dll, type = size, size_out = 60072 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Excel.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Excel.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Windows.resources.dll, type = size, size_out = 159808 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Windows.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Windows.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\no\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll, type = size, size_out = 60072 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Excel.resources.dll, type = size, size_out = 69696 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Excel.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Excel.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Windows.resources.dll, type = size, size_out = 195240 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Windows.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Windows.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Document.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Document.resources.dll, type = size, size_out = 254016 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Document.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Document.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.Mashup.Document.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.MashupEngine.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.MashupEngine.resources.dll, type = size, size_out = 715432 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.MashupEngine.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.MashupEngine.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\uk\Microsoft.MashupEngine.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Excel.resources.dll, type = size, size_out = 65600 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Excel.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Excel.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Excel.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Windows.resources.dll, type = size, size_out = 170664 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Windows.resources.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Windows.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\vi\Microsoft.Mashup.Client.Windows.resources.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\es\PowerViewRes.es.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ja\PowerViewRes.ja.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\kk\PowerViewRes.kk.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ko\PowerViewRes.ko.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\lt\PowerViewRes.lt.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\Microsoft.ReportingServices.ProgressiveProcessing.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\Microsoft.ReportingServices.ProgressiveProcessing.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ms\PowerViewRes.ms.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\nl\PowerViewRes.nl.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\no\PowerViewRes.no.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\pl\PowerViewRes.pl.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\cs\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\cs\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\da\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\da\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\de\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\de\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\el\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\el\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\es\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\es\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\et\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\et\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\eu\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\eu\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\lt\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\lt\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\lv\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\lv\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.BackEnd.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.BackEnd.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.Common.FrontEnd.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Excel.Common.FrontEnd.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Modeler.UI.rll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.AnalysisServices.Modeler.UI.rll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe7c
867 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 4
Fn
File Create filename = C:\Boot\BCD, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\BCD.LOG1, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG1, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\BCD.LOG2, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG2, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = size, size_out = 77664 True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\cs-CZ\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\memtest.exe.mui, type = size, size_out = 45472 True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\cs-CZ\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\da-DK\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\da-DK\bootmgr.exe.mui, type = size, size_out = 75616 True 1
Fn
File Get Info filename = C:\Boot\da-DK\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\da-DK\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\da-DK\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\da-DK\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\da-DK\memtest.exe.mui, type = size, size_out = 45472 True 1
Fn
File Get Info filename = C:\Boot\da-DK\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\da-DK\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\da-DK\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\de-DE\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\de-DE\bootmgr.exe.mui, type = size, size_out = 79200 True 1
Fn
File Get Info filename = C:\Boot\de-DE\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\de-DE\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\de-DE\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\de-DE\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\de-DE\memtest.exe.mui, type = size, size_out = 45984 True 1
Fn
File Get Info filename = C:\Boot\de-DE\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\de-DE\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\de-DE\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Move source_filename = C:\Boot\Fonts\chs_boot.ttf, destination_filename = C:\Boot\Fonts\chs_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, type = size, size_out = 186944 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, type = size, size_out = 265792 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, type = size, size_out = 455744 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, type = size, size_out = 619584 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, type = size, size_out = 158272 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, type = size, size_out = 123456 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, type = size, size_out = 19008 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\ext\sunjce_provider.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jfr\default.jfc.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jfr\profile.jfc.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\logging.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.access.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.password.template.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\management\management.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\management\snmp.acl.template.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\meta-index.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\net.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\psfont.properties.ja.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\resources.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\resources.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\rt.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\rt.jar.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\blacklist.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\blacklisted.certs.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\security\cacerts.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\client\AppvIsvSubsystems32.dll, destination_filename = C:\Program Files\Microsoft Office\root\client\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\client\AppvIsvSubsystems64.dll, destination_filename = C:\Program Files\Microsoft Office\root\client\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\client\mfc140u.dll, destination_filename = C:\Program Files\Microsoft Office\root\client\mfc140u.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BABY_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CARBN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CMNTY_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EAST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EXPLR_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FALL_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FINCL_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FINCL_02.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\GRDEN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\GRID_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HTECH_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\INDST_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\JAVA_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Flattener\AppVOpcServices.dll, destination_filename = C:\Program Files\Microsoft Office\root\Flattener\AppVOpcServices.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Flattener\AppVOpcServices.dll.manifest.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Flattener\AppVPackaging.dll.manifest.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-bridge-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-root-bridge-test.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-root.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-stil.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\client-issuance-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365BusinessR_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365HomePremR_SubTest2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OutlookR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectProCO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp3-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp4-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp5-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp6-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp6-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp6-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp6-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Trial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdCO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioStdR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Lync.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_authored.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_Common.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_licensing.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_mondoww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Office.x-none.msi.16_postcommon.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\office32ww.msi.16_crossbitness.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\office32ww.msi.16_office32ww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\office32ww.msi.16_office32ww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\OneNote.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\OneNote.x-none.msi.16_OneNote.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\OSM.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\OSMUX.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Outlook.x-none.msi.16_mondoww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Outlook.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Outlook.x-none.msi.16_PostCommon.Outlook.x-none.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\PowerPivot.x-none.msi.16_mondoww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\PowerPivot.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\PowerPoint.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Project.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Publisher.x-none.msi.16_mondoww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Publisher.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Visio.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Visio.x-none.msi.16_PostCommon.Visio.x-none.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Word.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ACCESS12.ACC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\AEC.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\AECUTILS.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ASSET.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\BSTORM.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\CALEVENT.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\GrooveIntlResource.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MOVE.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSACCESS.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSACCESS_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSACCESS_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSACCESS_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSACCESS_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSO.ACL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSOUC.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSOUC_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSOUC_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSOUC_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSOUC_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB.OPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\MSPUB_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\NETWORK1.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\NETWORK2.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\NETWORK3.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONENOTE.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONENOTE_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONENOTE_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONENOTE_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONENOTE_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ORGCH.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ORGCHART.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\el\PowerViewRes.el.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\et\PowerViewRes.et.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\eu\PowerViewRes.eu.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\fi\PowerViewRes.fi.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\fr\PowerViewRes.fr.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\gl\PowerViewRes.gl.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\he\PowerViewRes.he.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\pt\PowerViewRes.pt.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\pt-PT\PowerViewRes.pt-PT.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ro\PowerViewRes.ro.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ru\PowerViewRes.ru.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sk\PowerViewRes.sk.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\sl\PowerViewRes.sl.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\he\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\he\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hi\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hi\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hr\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\hr\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ja\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ja\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\kk\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\kk\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ko\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ko\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe80
737 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 4
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = size, size_out = 95648 True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, type = size, size_out = 63552 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, type = size, size_out = 21056 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, type = size, size_out = 34368 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, type = size, size_out = 15936 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, type = size, size_out = 159808 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, type = size, size_out = 206912 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, type = size, size_out = 142400 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\jce.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\MUSIC_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\URBAN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\VCTRN_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WNTER_01.MID.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Banded Edge.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Extreme Shadow.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Frosted Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Glossy.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Glow Edge.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Grunge Texture.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Inset.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Milk Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Office 2007 - 2010.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Reflection.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Riblet.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Smokey Glass.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Subtle Solids.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Effects\Top Shadow.eftx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Flattener\Microsoft.AppV.Modernizer.ManagedCpp.dll, destination_filename = C:\Program Files\Microsoft Office\root\Flattener\Microsoft.AppV.Modernizer.ManagedCpp.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi, destination_filename = C:\Program Files\Microsoft Office\root\Integration\C2RInt.16.msi.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Integration\OneDriveSetup.exe, destination_filename = C:\Program Files\Microsoft Office\root\Integration\OneDriveSetup.exe.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Integration\QFE31927.msp, destination_filename = C:\Program Files\Microsoft Office\root\Integration\QFE31927.msp.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Integration\QFE31928.msp, destination_filename = C:\Program Files\Microsoft Office\root\Integration\QFE31928.msp.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Integration\SPPRedist.msi, destination_filename = C:\Program Files\Microsoft Office\root\Integration\SPPRedist.msi.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows6.1-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows6.1-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows8-RT-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows8-RT-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows8.1-KB2999226-x64.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\Windows8.1-KB2999226-x86.msu.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\AccessR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ExcelVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp3-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_OEM_Perp4-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Retail3-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\HomeBusinessR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTest2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\MondoVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_Subscription5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial1-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial3-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial4-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\O365SmallBusPremR_SubTrial5-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteFreeR_Bypass-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\OneNoteR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\PowerPointVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalPipcR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProfessionalR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProjectStdVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusMSDNR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusMSDNR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusMSDNR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusMSDNR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\ProPlusR_OEM_Perp3-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\SkypeforBusinessEntryR_PrepidBypass-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardMSDNR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardR_Trial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_KMS_Client-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_KMS_Client-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_KMS_Client-ul.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_MAK-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_MAK-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_MAK-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\StandardVL_MAK-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProCO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProDemoR_BypassTrial180-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProDemoR_BypassTrial180-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProDemoR_BypassTrial180-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProMSDNR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProMSDNR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProMSDNR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProMSDNR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_Subscription-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_Subscription-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_Subscription-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTest-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTest-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTest-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTrial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTrial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProO365R_SubTrial-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Grace-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Grace-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_OEM_Perp-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_OEM_Perp-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_OEM_Perp-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_OEM_Perp-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail2-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail2-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail2-ul-oob.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Retail2-ul-phn.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Trial-pl.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Licenses16\VisioProR_Trial-ppd.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\accessmui.msi.16_accessmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\accessmuiset.msi.16_accessmuiset.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\branding.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\dcfmui.msi.16_dcfmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\excelmui.msi.16_excelmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\groovemui.msi.16_groovemui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\lyncmui.msi.16_lyncmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\office32mui.msi.16_office32mui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\officemui.msi.16_AppXManifestLoc.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\officemui.msi.16_officemui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\officemui.msi.16_PostCommon.Office.MUI.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\officemuiset.msi.16_officemuiset.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\onenotemui.msi.16_onenotemui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\osmmui.msi.16_osmmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\osmuxmui.msi.16_osmuxmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\outlookmui.msi.16_outlookmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\powerpointmui.msi.16_powerpointmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\projectmui.msi.16_projectmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\Proof.Culture.msi.16_proof.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\proofing.msi.16_proofing.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\publishermui.msi.16_publishermui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\visiomui.msi.16_visiomui.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\visiomui.msi.16_visiomui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\en-us\wordmui.msi.16_wordmui.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\es-es\Proof.Culture.msi.16_proof.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\fr-fr\Proof.Culture.msi.16_proof.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Access.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\DCF.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Excel.x-none.msi.16_mondoww.mcxml, destination_filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Excel.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\mcxml\x-none\Groove.x-none.msi.16_mondoww.mcxml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ORGPOS.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_BASIC_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_BASIC_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINE.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINEG.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINEG_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINEG_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINEG_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINEG_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINE_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINE_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINE_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKYPEFB_ONLINE_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SPACE.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeAccess.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeExcel.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOneNote.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlook.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookAddr.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookAppt.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookMail.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookMailRead.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookMeetingReqRead.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookMeetingReqSend.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeOutlookTask.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMePowerPoint.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeProject.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeVisio.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TellMeWord.nrr.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TIMESOLN.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VALVE.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISCOLOR.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_PRM.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_PRM_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_PRM_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_PRM_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_PRM_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_STD.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_STD_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_STD_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_STD_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO_STD_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISUTILS.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISWEB.VSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WDALLLNK.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WDERRLNK.VRD.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_F_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_K_COL.HXK.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_STD.HXS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_STD_COL.HXC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WINPROJ_STD_COL.HXT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Client.Excel.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Client.Excel.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Client.Windows.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Client.Windows.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Document.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Document.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.ScriptDom.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.ScriptDom.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.MashupEngine.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.MashupEngine.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ar\PowerViewRes.ar.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\bg\PowerViewRes.bg.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\ca\PowerViewRes.ca.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\cs\PowerViewRes.cs.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\da\PowerViewRes.da.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\de\PowerViewRes.de.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\tr\PowerViewRes.tr.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\uk\PowerViewRes.uk.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\vi\PowerViewRes.vi.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\zh-CHS\PowerViewRes.zh-CHS.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\zh-CHT\PowerViewRes.zh-CHT.xap.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ar\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ar\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\bg\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\bg\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ca\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ca\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.Office.Interop.Excel.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.Office.Interop.Excel.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.ReportingServices.QueryDesigners.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.ReportingServices.QueryDesigners.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.reportviewer.common.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Microsoft.reportviewer.common.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ms\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ms\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\nl\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\nl\Microsoft.AnalysisServices.Excel.Common.FrontEnd.resources.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe84
498 0
»
Category Operation Information Success Count Logfile
Thread 0xe88
936 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 6
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml, type = size, size_out = 903 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\keypadbase.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml, type = size, size_out = 247 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\baseAltGr_rtl.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml, type = size, size_out = 3524 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, type = size, size_out = 3529 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_ca.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml, type = size, size_out = 738 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_heb.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml, type = size, size_out = 804 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml, type = size, size_out = 488 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_kor.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Get Info type = size, size_out = 12332 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285820.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285822.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287018.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287019.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287408.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287415.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287417.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287641.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287642.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287643.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287644.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287645.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0289430.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0290548.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0291794.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0292248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0292270.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0292272.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0292278.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0292286.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0293800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0293832.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0294989.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0294991.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0295069.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309904.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309920.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313896.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313965.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313970.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313974.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0314068.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0315580.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0315612.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0318448.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0318804.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0318810.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0321179.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0324694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0324704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0337280.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341328.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341344.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341439.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341447.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382939.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382942.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382944.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382947.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382948.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382950.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382954.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382955.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382957.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382958.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382959.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382960.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382961.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382962.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382965.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382966.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382967.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382968.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382969.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382970.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384862.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384885.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384888.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384900.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00388_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02373_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02450_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02451_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00013_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00014_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00034_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00049_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00050_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00052_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00231_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE01191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE01661_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE01797_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02120_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02169_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02263_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02267_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02738U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02740G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02740U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02742G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02742U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02743G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF, type = size, size_out = 24187 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP, type = size, size_out = 32132 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02746U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF, type = size, size_out = 24720 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP, type = size, size_out = 32400 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02748U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF, type = size, size_out = 34709 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP, type = size, size_out = 108504 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02754U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02757U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02758U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02759J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02810J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02829J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02845G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02897J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03011U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03012U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03014_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03041I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03143I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03205I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03224I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03379I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03380I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00483_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00486_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00505_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00513_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00555_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00603_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00610_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00629_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00633_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00638_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00656_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00668_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00670_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00671_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00683_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00694_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00704_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00726_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00728_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00732_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00734_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00735_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02048_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02051_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02054_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02055_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02067_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02094_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02227_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02228_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02233_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02253_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02261_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02263_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02265_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02268_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02269_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02276_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02431_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02437_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00241_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00246_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00253_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00255_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00330_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00411_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00687_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN01164_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN01165_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN01308_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00095_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00097_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00116_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00126_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00178_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00232_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00233_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00402_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00482_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TR00494_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01219_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01237_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02082_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02085_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02097_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02106_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02116_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02134_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02187_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02198_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02201_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02214_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02218_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Facet.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Integral.thmx, destination_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Integral.thmx.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Ion Boardroom.thmx, destination_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Ion Boardroom.thmx.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Orange Red.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Orange.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Paper.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Red Orange.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Red Violet.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Red.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Slipstream.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Violet II.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Violet.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Yellow Orange.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Yellow.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Arial Black-Arial.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Arial-Times New Roman.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Arial.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Calibri Light-Constantia.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Calibri-Cambria.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Calibri.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Cambria.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Candara.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Century Gothic-Palatino Linotype.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Century Gothic.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Century Schoolbook.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Consolas-Verdana.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Constantia-Franklin Gothic Book.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Corbel.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Franklin Gothic.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.groovemui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\Bibliography\BIBFORM.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\CollectSignatures_Init.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\CollectSignatures_Sign.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\CT_ROOTS.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DataServices\+Connect to New Data Source.odc.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DataServices\+NewSQLServerConnection.odc.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DataServices\DESKTOP.INI.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DBSAMPLE.MDB.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\DEFAULT.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EADOCUMENTAPPROVAL_INIT.XSN.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EADOCUMENTAPPROVAL_REVIEW.XSN.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\EXPTOOWS.XLA.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\FOREST.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\GANTT.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\Invite or Link.one.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\JADE.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\NETWORK.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OCCMPVRD.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OCMODVRD.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\officeinventoryagentfallback.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\officeinventoryagentlogon.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ONGuide.onepkg.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTFORM.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLPERF.H.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\OUTLPERF.INI.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PASSPORT.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PASTEL.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME41.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR50F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR20F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR21F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR22F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR23F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR24F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR25F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR26F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR27F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR28F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR29F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR2B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR2F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR30F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR31F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR32F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR33F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR34F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR35F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR36F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR37F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR38F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR39F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR3B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR3F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR40F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR41F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR42F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR43B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR43F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR44B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SUNSET.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\sql70.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe8c
1599 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 5
Fn
File Create filename = C:\Boot\BCD.LOG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = size, size_out = 4662 True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, type = size, size_out = 392 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 4
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105292.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105292.WMF, type = size, size_out = 14868 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105292.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105292.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, type = size, size_out = 13784 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, type = size, size_out = 3020 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, type = size, size_out = 7632 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, type = size, size_out = 9048 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF, type = size, size_out = 14132 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF, type = size, size_out = 27084 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216612.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216874.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217872.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0238983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241781.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0250504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0250997.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0251007.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0252629.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0252669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0278702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0279644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0280468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281008.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281243.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281630.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281632.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0281640.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0282126.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0282928.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0282932.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285462.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285782.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285792.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0285808.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0296277.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0296279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0296288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297229.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297269.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297725.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297727.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297757.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0297759.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0300862.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0301044.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0301052.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0301418.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0301432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0304371.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0304405.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0304853.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0304861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0304875.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309480.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309567.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309585.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309598.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309664.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309705.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386120.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01357_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01368_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01421_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01468_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01470_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01472_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01473_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01474_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01627_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01680_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF, type = size, size_out = 3208 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01682_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF, type = size, size_out = 5316 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01701_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF, type = size, size_out = 1120 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01848_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02368_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\sl\Microsoft.Mashup.Client.Excel.resources.dll, type = size, size_out = 3368 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02368_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02368_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02368_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02368_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF, type = size, size_out = 3188 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02371_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF, type = size, size_out = 3032 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02384_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF, type = size, size_out = 2376 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02386_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF, type = size, size_out = 3204 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02388_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF, type = size, size_out = 2860 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02389_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF, type = size, size_out = 3684 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02398_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02400_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02404_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02405_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02407_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02413_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02417_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02423_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02424_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02426_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02431_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02435_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02441_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02443_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02446_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02448_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02028K.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02039U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02040U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02053J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02058U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02062U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02069J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02071U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02074U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02208U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02223U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02291U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02398U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02412K.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02417U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02466U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02470U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02503U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02567J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02736G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02736U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02755U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL01395_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL01565_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00017_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00018_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00159_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00166_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00168_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00177_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00183_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00190_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00191_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00192_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00194_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00197_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00199_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00200_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00208_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00212_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00221_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00222_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00223_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01236_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01560_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01561_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01563_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01566_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01568_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01569_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01575_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01777_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01785_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01805_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01905_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01954_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02009_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02022_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02024_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02025_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02028_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02045_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF, type = size, size_out = 5978 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00095_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF, type = size, size_out = 7186 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00211_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF, type = size, size_out = 4644 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00217_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF, type = size, size_out = 7104 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00218_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF, type = size, size_out = 1848 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00231_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF, type = size, size_out = 3176 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00234_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF, type = size, size_out = 1429 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143746.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF, type = size, size_out = 4561 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143748.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF, type = size, size_out = 4899 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143749.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143750.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143752.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143753.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143754.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143758.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00516L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00531L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00673L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00703L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00760L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB00780L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB01741L.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02039_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02055_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02073_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02074_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\WB02077_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.excelmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\BW.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME14.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME15.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME16.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME17.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME18.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME19.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME20.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME21.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME22.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME23.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME24.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME25.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME26.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME27.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME28.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME29.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME30.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME31.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME32.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME33.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME34.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME35.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME36.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME37.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME38.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME39.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME40.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR35F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR36B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR36F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR37F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR38F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR39F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR3B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR3F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR40F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR41F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR42F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR43B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR43F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR44B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR44F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR45B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR45F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR46B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR46F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR47B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR47F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR48B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR48F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR49B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR49F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR4B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TERRCOTT.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\Sybase.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\trdtv2r41.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\cs\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\da\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\de\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\el\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\en\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\es\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\et\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\eu\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fi\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\fr\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\gl\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\he\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe90
1050 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 6
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, type = size, size_out = 791421 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = size, size_out = 27045 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, type = size, size_out = 111320 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = size, size_out = 48936 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, type = size, size_out = 46622 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = size, size_out = 84190 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, type = size, size_out = 180172 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\correct.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341448.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341455.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341475.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341499.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341534.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341551.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341554.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341557.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341559.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341561.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341634.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341636.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341645.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341653.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341654.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341738.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341742.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382836.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382925.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382926.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382927.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382930.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382931.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382938.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00389_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00391_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00394_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00395_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00396_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00417_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00433_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00438_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00452_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00454_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00458_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00462_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00487_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00494_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00512_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00523_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00525_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00530_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00532_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00538_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00641_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00784_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00798_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00806_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00807_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00808_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00809_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00810_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00932_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01064_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01066_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01069_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01123_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01126_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01130_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01141_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01148_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01149_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01152_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01154_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01157_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01158_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01161_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01164_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01293_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01354_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01356_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02270_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02278_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02280_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02282_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02285_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02287_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02288_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02293_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02296_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02369_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02522_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02950_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE02957_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03236_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03241_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03257_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03331_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03339_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03451_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03459_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03464_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03466_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03470_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03513_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03668_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03731_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE03795_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE04050_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE05665_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01046J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02749U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02750G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02750U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02752G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02752U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02753U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03425I.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PRRT.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PRRTINST.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PSRETRO.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PSSKETLG.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PSSKETSM.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PSWAVY.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\RE00006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\RECYCLE.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00256_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00260_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00268_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00286_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00298_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00308_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00345_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00452_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL00712_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL01040_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL01041_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SL01394_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF, type = size, size_out = 5896 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00941_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF, type = size, size_out = 4708 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00942_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF, type = size, size_out = 7556 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00943_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF, type = size, size_out = 44570 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01044_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF, type = size, size_out = 23352 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO01063_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF, type = size, size_out = 10084 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00795_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00882_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01006_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01252_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01253_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01462_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01491_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01563_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01572_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY01590_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TAIL.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00011_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00014_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\TN00018_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01740_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01742_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01743_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01744_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01745_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01746_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01747_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01748_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01749_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01750_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01751_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01770_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01838_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01839_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01840_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01842_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01843_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB02229_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WHIRL1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WHIRL2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WING1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WING2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143743.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143744.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\Publisher\Backgrounds\J0143745.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Garamond-TrebuchetMs.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Garamond.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Georgia.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Gill Sans MT.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Office 2007 - 2010.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Times New Roman-Arial.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\TrebuchetMs.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Tw Cen MT-Rockwell.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Fonts\Tw Cen MT.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Wisp.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Flattener\CommonSequencingProperties.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Flattener\Flattener.exe.config.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win10.mp4.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win10_RTL.mp4.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win7.wmv.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win7_RTL.wmv.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win8.mp4.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\fre\StartMenu_Win8_RTL.mp4.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.accessmuiset.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.dcfmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.lyncmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.office32mui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.office32ww.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.officemui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.officemuiset.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.onenotemui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.osmmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.osmuxmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.outlookmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.powerpointmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Project.Project.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.projectmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Proof.Culture.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Proof.Culture.msi.16.es-es.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.proofing.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.publishermui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.shared.Office.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Visio.Visio.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.visiomui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Word.Word.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.wordmui.msi.16.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\loc\AppXManifestLoc.en-us.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\BASIC.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR1B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR1F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR20F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR21F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR22F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR23F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR24F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR25F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR26F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR27F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR28B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR28F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR29B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR29F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR2B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR2F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR30B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR30F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR31B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR31F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR32B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR32F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR33B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR33F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR34B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR34F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR35B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR4F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR51B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR51F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR5B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR5F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR6B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR6F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR7B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR7F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR8B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR8F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR9B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR9F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPAPERS.INI.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR00.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR10F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR11F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR12F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR13F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR14F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR15F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR16F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR17F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR18F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR19F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR1B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR1F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR9F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\basicelegant.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\basicsimple.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\basicstylish.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwcapitalized.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwclassic.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwnumbered.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\casual.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\centered.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\Classic.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\Default.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linesdistinctive.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linessimple.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linesstylish.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\minimalist.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\shaded.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\word2013.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\word2013bw.dotx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ReviewRouting_Init.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ReviewRouting_Review.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\ROSE.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SKY.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SPRING.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SPS.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\STEEL.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\SUNNY.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TelemetryLog.xltx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\VISIO.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\WDCMPVRD.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\Xlate_Complete.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\Xlate_Init.xsn.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\AccessWeb\CLNTWRAP.HTM.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\AccessWeb\RPT2HTM4.XSL.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZLIB.ACCDE, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZLIB.ACCDE.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZMAIN.ACCDE, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZMAIN.ACCDE.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZTOOL.ACCDE, destination_filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZTOOL.ACCDE.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\UTILITY.ACCDA.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\MSOSEC.XML.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power View Excel Add-in\BI-Report.png.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ar\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\bg\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\ca\LocalizedStrings.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\as80.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\as90.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\db2v0801.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\hive.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\Informix.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\msjet.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\orcl7.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\sql2000.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\sql90.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe94
1072 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = size, size_out = 129 True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = file_attributes True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 5
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml, type = size, size_out = 384 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\keypad\ea.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, type = size, size_out = 7505 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Stationery\Stars.jpg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\Services\verisign.bmp, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\Services\verisign.bmp, type = size, size_out = 2702 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\Services\verisign.bmp, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\Services\verisign.bmp.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\Services\verisign.bmp, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\adojavas.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adojavas.inc, type = size, size_out = 14856 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adojavas.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adojavas.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\adojavas.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\adovbs.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adovbs.inc, type = size, size_out = 15195 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adovbs.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\adovbs.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\adovbs.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, type = size, size_out = 630 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, type = size, size_out = 623 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213243.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228823.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228959.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232171.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232393.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232395.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232795.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232797.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232803.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0233512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0233665.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0233992.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0234000.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0234001.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0234376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0237225.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0237228.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0237336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0237759.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0238333.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0238927.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0238959.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239057.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239079.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239935.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239941.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239943.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239951.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239955.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239965.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239967.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239973.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239975.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0239997.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0240157.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0240175.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0240189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0240291.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241019.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241037.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241043.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241077.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0241773.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386267.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386270.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386485.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386764.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387337.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387578.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387591.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387604.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387882.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0390072.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0400001.PNG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0400002.PNG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0400003.PNG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0400004.PNG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0400005.PNG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\MP00021_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\MP00132_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\MP00646_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00042_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00057_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00058_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00068_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00238_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA00330_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01358_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01361_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01849_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01852_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01858_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA01866_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02009_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02041_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02066_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02091_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02092_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02093_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02124_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02125_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02126_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02127_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02262_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02264_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02356_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00272_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00468_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00478_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00485_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00489_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00531_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00542_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00555_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00559_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00563_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00578_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00608_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00633_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00640_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00668_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00685_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00686_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00693_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00720_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00723_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00726_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00737_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00833_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00898_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00934_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE00998_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE01160_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE01172_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE05710_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE05869_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE05870_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE05930_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE06049_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PE06450_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH00601G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH00780U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01035U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01179J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01213K.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01221K.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01235U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01236U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01239K.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01247U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01255G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01265U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01332U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01478U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01562U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01607U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01931J.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02756U.BMP.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00257_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00289_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00299_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00305_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00333_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00345_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00350_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00352_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00364_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00367_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00373_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00382_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00390_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00391_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00416_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00423_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00444_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00452_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00453_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00454_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00466_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00476_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00479_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00736_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00768_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00783_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00820_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00828_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00834_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00837_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00910_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00911_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00913_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00914_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00915_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00916_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00917_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00918_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00935_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO00938_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02439_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02464_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02465_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02578_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02617_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02790_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02791_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02793_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02794_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02862_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02886_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SO02958_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\STUBBY1.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\STUBBY2.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00110_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00127_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00132_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00170_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00560_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00642_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00788_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\SY00792_.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01238_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01239_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01240_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01241_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01242_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01243_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01244_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01245_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01246_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01253_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01268_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01292_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01293_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01294_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01295_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01296_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01297_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01298_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01299_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01300_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01301_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01304G.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01330_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\WB01734_.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Ion.thmx, destination_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Ion.thmx.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx, type = size, size_out = 326027 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx, type = size, size_out = 8705569 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx, destination_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx, type = size, size_out = 1623260 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx, destination_filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx, type = size, size_out = 864810 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml, type = size, size_out = 740 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Aspect.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml, type = size, size_out = 744 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Green.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue II.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue Warm.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Blue.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Grayscale.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Green Yellow.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Green.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Marquee.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Median.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Document Themes 16\Theme Colors\Office 2007 - 2010.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Integration\C2RManifest.Groove.Groove.x-none.msi.16.x-none.xml.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\COFFEE.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PREVIEWTEMPLATE.POTX.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PREVIEWTEMPLATE2.POTX.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PRIMARY.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLN.DOC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLN.PPT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLN.XLS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLV.DOC.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLV.PPT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLV.XLS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHKEY.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHLEX.DAT, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHLEX.DAT.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHLTS.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHPHN.DAT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHSRN.DAT, destination_filename = C:\Program Files\Microsoft Office\root\Office16\1033\PSRCHSRN.DAT.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\FONTSCHM.INI.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME01.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME02.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME03.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME04.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME05.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME06.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME07.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME08.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME09.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME10.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME11.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME12.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME13.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME42.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME43.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME44.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME45.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME46.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME47.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME48.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME49.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME50.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME51.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME52.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME53.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME54.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBFTSCM\SCHEME55.CSS.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PAPERS.INI.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR10F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR11F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR12F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR13F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR14F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR15F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR16F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR17F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR18F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR19F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\PDIR50B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR44F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR45B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR45F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR46B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR46F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR47B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR47F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR48B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR48F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR49B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR49F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR4B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR4F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR50B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR50F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR51B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR51F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR5B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR5F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR6B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR6F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR7B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR7F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR8B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR8F.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\PUBSPAPR\ZPDIR9B.GIF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\1033\TelemetryDashboard.xltx.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\sqlpdw.xsl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Thread 0xe98
498 0
»
Category Operation Information Success Count Logfile
Process #6: hgaibc.exe
111 0
»
Information Value
ID #6
File Name c:\users\fd1hvy\appdata\roaming\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:32, Reason: Autostart
Unmonitor End Time: 00:02:36, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0xe34
Parent PID 0x9d4 (c:\windows\explorer.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E38
0x E3C
Memory Dumps
»
Name Start VA End VA Dump Reason PE Rebuilds Bitness Entry Points AV YARA Actions
hgaibc.exe 0x00400000 0x00418FFF Process Termination - 32-bit - False False
Threads
Thread 0xe38
111 0
»
Category Operation Information Success Count Logfile
Module Load module_name = kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x770bed70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x77066760 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x770bf090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersion, address_out = 0x770656c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x770646b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x770bf180 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x770657f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreatePipe, address_out = 0x77064590 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringW, address_out = 0x77064430 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringA, address_out = 0x77064410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x77065010 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Module Load module_name = advapi32.dll, base_address = 0x75b90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Module Load module_name = user32.dll, base_address = 0x774c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Module Load module_name = Shell32.dll, base_address = 0x744f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Module Load module_name = ntdll.dll, base_address = 0x77850000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Module Load module_name = mpr.dll, base_address = 0x74250000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Module Load module_name = ws2_32.dll, base_address = 0x76f10000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = socket, address_out = 0x76f24510 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = send, address_out = 0x76f15030 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = recv, address_out = 0x76f20c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = connect, address_out = 0x76f15410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = closesocket, address_out = 0x76f20910 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = inet_addr, address_out = 0x76f29160 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = ntohl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htonl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htons, address_out = 0x76f28ff0 True 1
Fn
System Get Time type = Performance Ctr, time = 7423771604 True 1
Fn
System Get Time type = Ticks, time = 74203 True 3
Fn
System Get Info type = Operating System True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE True 1
Fn
System Get Info type = Operating System True 1
Fn
Process #7: cmd.exe
284 0
»
Information Value
ID #7
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:33, Reason: Child Process
Unmonitor End Time: 00:02:58, Reason: Self Terminated
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0xe40
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x E44
0x EC0
Threads
Thread 0xe44
284 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x7ff695310000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff8c81c0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\WINDOWS\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
System Get Info type = Operating System True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 38 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 52 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff8c81c0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7ff8c81de830 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x7ff8c81de300 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x7ff8c5880a40 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 24 True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\WINDOWS\system32\mode.com, os_pid = 0xed8, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Load module_name = NTDLL.DLL, base_address = 0x7ff8c85b0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ntdll.dll, function = NtQueryInformationProcess, address_out = 0x7ff8c86556b0 True 1
Fn
Process Get Info type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory Read process_name = C:\WINDOWS\system32\mode.com, address = 1083334918144, size = 1952 True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 36 True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\WINDOWS\system32\vssadmin.exe, os_pid = 0xf98, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Process Get Info type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory Read process_name = C:\WINDOWS\system32\vssadmin.exe, address = 476233924608, size = 1952 True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000002 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
Process #10: mode.com
0 0
»
Information Value
ID #10
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:41, Reason: Child Process
Unmonitor End Time: 00:02:49, Reason: Self Terminated
Monitor Duration 00:00:07
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xed8
Parent PID 0xe40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x EDC
0x EE0
Process #11: vssadmin.exe
0 0
»
Information Value
ID #11
File Name c:\windows\system32\vssadmin.exe
Command Line vssadmin delete shadows /all /quiet
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:51, Reason: Child Process
Unmonitor End Time: 00:02:57, Reason: Self Terminated
Monitor Duration 00:00:05
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xf98
Parent PID 0xe40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x F9C
0x FB8
0x FC4
0x FD0
0x FD4
Process #12: hgaibc.exe
29163 0
»
Information Value
ID #12
File Name c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe
Command Line "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe" -a
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:57, Reason: Child Process
Unmonitor End Time: 00:03:22, Reason: Terminated by Timeout
Monitor Duration 00:00:25
OS Process Information
»
Information Value
PID 0x2a8
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 32-bit
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C24
0x 380
0x C5C
0x 8BC
0x C68
0x 998
0x 638
0x C84
0x 970
0x 964
0x A94
0x 908
0x A8C
0x A90
0x C4C
0x 90C
0x 904
0x 4F4
Threads
Thread 0xc24
343 0
»
Category Operation Information Success Count Logfile
Module Load module_name = kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcAddress, address_out = 0x770651b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleHandleW, address_out = 0x770650d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindNextFileW, address_out = 0x770bee40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindClose, address_out = 0x770bed70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = MoveFileW, address_out = 0x7709e500 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileSizeEx, address_out = 0x770bef40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetModuleFileNameW, address_out = 0x77065090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetFileAttributesW, address_out = 0x770bef10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExitProcess, address_out = 0x77063cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCommandLineW, address_out = 0x77064cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameW, address_out = 0x770932c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetComputerNameA, address_out = 0x77093780 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateMutexW, address_out = 0x770beb70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenW, address_out = 0x77066c70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrlenA, address_out = 0x77066c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcess, address_out = 0x770bea10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForSingleObject, address_out = 0x770beca0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLogicalDrives, address_out = 0x77060d20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetTickCount, address_out = 0x770bdd50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteFileW, address_out = 0x770bed40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WideCharToMultiByte, address_out = 0x77066b10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = InitializeCriticalSectionAndSpinCount, address_out = 0x770bebb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Sleep, address_out = 0x77066760 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = LeaveCriticalSection, address_out = 0x7789b250 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReadFile, address_out = 0x770bf090 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateFileW, address_out = 0x770bed10 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenMutexW, address_out = 0x770bebf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = EnterCriticalSection, address_out = 0x7789b2d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WaitForMultipleObjects, address_out = 0x770bec80 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiW, address_out = 0x77066bf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = lstrcmpiA, address_out = 0x77066bd0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = DeleteCriticalSection, address_out = 0x7787fb90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ReleaseMutex, address_out = 0x770bec20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CloseHandle, address_out = 0x770beab0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVersion, address_out = 0x770656c0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateThread, address_out = 0x770646b0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ExpandEnvironmentStringsW, address_out = 0x77064a40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceCounter, address_out = 0x77065da0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = QueryPerformanceFrequency, address_out = 0x77065dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetCurrentProcessId, address_out = 0x770bea20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFileAttributesW, address_out = 0x770bf100 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetVolumeInformationW, address_out = 0x770bf020 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WriteFile, address_out = 0x770bf180 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetFilePointerEx, address_out = 0x770bf130 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetEndOfFile, address_out = 0x770bf0e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = FindFirstFileW, address_out = 0x770bedf0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetProcessHeap, address_out = 0x770651f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapReAlloc, address_out = 0x7788f630 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapAlloc, address_out = 0x77892dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = HeapFree, address_out = 0x770657f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreatePipe, address_out = 0x77064590 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SetHandleInformation, address_out = 0x770beae0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateProcessW, address_out = 0x77064610 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringW, address_out = 0x77064430 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CompareStringA, address_out = 0x77064410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = OpenProcess, address_out = 0x77065cc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = TerminateProcess, address_out = 0x770667e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetSystemTime, address_out = 0x770654e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = SystemTimeToFileTime, address_out = 0x770667a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetLastError, address_out = 0x77065010 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = CreateToolhelp32Snapshot, address_out = 0x7709edc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32NextW, address_out = 0x7709f8f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Process32FirstW, address_out = 0x7709f750 True 1
Fn
Module Load module_name = advapi32.dll, base_address = 0x75b90000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegOpenKeyExW, address_out = 0x75bae580 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegQueryValueExW, address_out = 0x75bae5a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegSetValueExW, address_out = 0x75baf530 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RegCloseKey, address_out = 0x75baed60 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x75baefb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x75baee90 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenSCManagerW, address_out = 0x75bb0540 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenServiceW, address_out = 0x75bafa20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CloseServiceHandle, address_out = 0x75bafc00 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ControlService, address_out = 0x75bc26d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = QueryServiceStatus, address_out = 0x75bb2380 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumDependentServicesW, address_out = 0x75bc2f70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = EnumServicesStatusExW, address_out = 0x75bafc80 True 1
Fn
Module Load module_name = user32.dll, base_address = 0x774c0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SystemParametersInfoW, address_out = 0x774ef210 True 1
Fn
Module Load module_name = Shell32.dll, base_address = 0x744f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = ShellExecuteExW, address_out = 0x74654730 True 1
Fn
Module Load module_name = ntdll.dll, base_address = 0x77850000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ntdll.dll, function = NtQuerySystemInformation, address_out = 0x778c2070 True 1
Fn
Module Load module_name = mpr.dll, base_address = 0x74250000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetCloseEnum, address_out = 0x74252640 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetOpenEnumW, address_out = 0x74252790 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\mpr.dll, function = WNetEnumResourceW, address_out = 0x74252410 True 1
Fn
Module Load module_name = ws2_32.dll, base_address = 0x76f10000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = WSAStartup, address_out = 0x76f15b40 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = socket, address_out = 0x76f24510 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = send, address_out = 0x76f15030 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = recv, address_out = 0x76f20c50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = connect, address_out = 0x76f15410 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = closesocket, address_out = 0x76f20910 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = gethostbyname, address_out = 0x76f46cb0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = inet_addr, address_out = 0x76f29160 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = ntohl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htonl, address_out = 0x76f149d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ws2_32.dll, function = htons, address_out = 0x76f28ff0 True 1
Fn
System Get Time type = Performance Ctr, time = 9800944433 True 1
Fn
System Get Time type = Ticks, time = 97968 True 3
Fn
System Get Info type = Operating System True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0A, desired_access = SYNCHRONIZE True 1
Fn
Mutex Open mutex_name = Global\syncronize_1TPBM0U, desired_access = SYNCHRONIZE True 1
Fn
System Get Info type = Operating System True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\WINDOWS\System32\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\WINDOWS\System32\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run True 1
Fn
Registry Write Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, value_name = hgaibc.exe, data = C:\WINDOWS\System32\hgaibc.exe, size = 60, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = 83, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Startup, data = %USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 94720 True 1
Fn
Data
File Write filename = C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 94720 True 1
Fn
Data
File Read filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 1048576, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, value_name = Common Startup, data = %ProgramData%\Microsoft\Windows\Start Menu\Programs\Startup, type = REG_EXPAND_SZ True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ True 1
Fn
File Create filename = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, desired_access = GENERIC_WRITE False 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 0 True 1
Fn
Process Create process_name = C:\WINDOWS\system32\cmd.exe, os_pid = 0xc40, startup_flags = STARTF_USESHOWWINDOW, STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Write size = 65 True 1
Fn
Data
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
Module Get Filename process_name = c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe, file_name_orig = C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\hgaibc.exe, size = 32767 True 1
Fn
System Sleep duration = -1 (infinite) False 1
Fn
Thread 0xc5c
3426 0
»
Category Operation Information Success Count Logfile
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - False 1
Fn
System Sleep duration = 500 milliseconds (0.500 seconds) True 1
Fn
Service Open Manager database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE False 1
Fn
Service Enumerate database_name = SERVICES_ACTIVE_DATABASE True 1
Fn
Process Enumerate Processes - True 2
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
Process Enumerate Processes - True 1
Fn
For performance reasons, the remaining 137 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xc68
30 0
»
Category Operation Information Success Count Logfile
System Get Computer Name result_out = NQDPDE True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 29
Fn
Thread 0x998
117 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 98421 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Get Time type = Ticks, time = 98671 True 1
Fn
System Get Time type = Ticks, time = 98937 True 1
Fn
System Get Time type = Ticks, time = 99312 True 1
Fn
System Get Time type = Ticks, time = 99875 True 2
Fn
System Get Time type = Ticks, time = 100171 True 1
Fn
System Get Time type = Ticks, time = 100468 True 1
Fn
System Get Time type = Ticks, time = 102046 True 2
Fn
System Get Time type = Ticks, time = 102843 True 1
Fn
System Get Time type = Ticks, time = 103265 True 2
Fn
System Get Time type = Ticks, time = 103734 True 1
Fn
System Get Time type = Ticks, time = 104734 True 2
Fn
System Get Time type = Ticks, time = 105156 True 1
Fn
System Get Time type = Ticks, time = 105593 True 1
Fn
System Get Time type = Ticks, time = 105890 True 2
Fn
System Get Time type = Ticks, time = 106078 True 1
Fn
System Get Time type = Ticks, time = 106203 True 1
Fn
System Get Time type = Ticks, time = 106375 True 1
Fn
System Get Time type = Ticks, time = 106562 True 1
Fn
System Get Time type = Ticks, time = 106953 True 2
Fn
System Get Time type = Ticks, time = 107156 True 1
Fn
System Get Time type = Ticks, time = 107343 True 1
Fn
System Get Time type = Ticks, time = 107468 True 1
Fn
System Get Time type = Ticks, time = 107609 True 1
Fn
System Get Time type = Ticks, time = 107765 True 1
Fn
System Get Time type = Ticks, time = 107875 True 1
Fn
System Get Time type = Ticks, time = 107984 True 2
Fn
System Get Time type = Ticks, time = 108093 True 1
Fn
System Get Time type = Ticks, time = 108203 True 1
Fn
System Get Time type = Ticks, time = 108312 True 1
Fn
System Get Time type = Ticks, time = 108421 True 1
Fn
System Get Time type = Ticks, time = 108718 True 1
Fn
System Get Time type = Ticks, time = 108828 True 1
Fn
System Get Time type = Ticks, time = 108968 True 1
Fn
System Get Time type = Ticks, time = 109078 True 2
Fn
System Get Time type = Ticks, time = 109218 True 1
Fn
System Get Time type = Ticks, time = 109328 True 1
Fn
System Get Time type = Ticks, time = 109437 True 1
Fn
System Get Time type = Ticks, time = 109546 True 1
Fn
System Get Time type = Ticks, time = 109656 True 1
Fn
System Get Time type = Ticks, time = 109765 True 1
Fn
System Get Time type = Ticks, time = 109875 True 1
Fn
System Get Time type = Ticks, time = 110000 True 1
Fn
System Get Time type = Ticks, time = 110109 True 2
Fn
System Get Time type = Ticks, time = 110218 True 1
Fn
System Get Time type = Ticks, time = 110328 True 1
Fn
System Get Time type = Ticks, time = 110437 True 1
Fn
System Get Time type = Ticks, time = 110546 True 1
Fn
System Get Time type = Ticks, time = 110656 True 1
Fn
System Get Time type = Ticks, time = 110765 True 1
Fn
System Get Time type = Ticks, time = 110875 True 1
Fn
System Get Time type = Ticks, time = 110984 True 1
Fn
System Get Time type = Ticks, time = 111093 True 1
Fn
System Get Time type = Ticks, time = 111265 True 2
Fn
System Get Time type = Ticks, time = 111390 True 1
Fn
System Get Time type = Ticks, time = 111500 True 1
Fn
System Get Time type = Ticks, time = 111703 True 1
Fn
System Get Time type = Ticks, time = 111828 True 1
Fn
System Get Time type = Ticks, time = 111937 True 1
Fn
System Get Time type = Ticks, time = 112046 True 1
Fn
System Get Time type = Ticks, time = 112156 True 1
Fn
System Get Time type = Ticks, time = 112265 True 1
Fn
System Get Time type = Ticks, time = 112375 True 2
Fn
System Get Time type = Ticks, time = 112500 True 1
Fn
System Get Time type = Ticks, time = 114937 True 2
Fn
System Get Time type = Ticks, time = 115078 True 1
Fn
System Get Time type = Ticks, time = 115187 True 1
Fn
System Get Time type = Ticks, time = 115296 True 1
Fn
System Get Time type = Ticks, time = 115406 True 1
Fn
System Get Time type = Ticks, time = 115531 True 1
Fn
System Get Time type = Ticks, time = 115640 True 1
Fn
System Get Time type = Ticks, time = 115750 True 1
Fn
System Get Time type = Ticks, time = 115875 True 1
Fn
System Get Time type = Ticks, time = 115984 True 2
Fn
System Get Time type = Ticks, time = 116093 True 1
Fn
System Get Time type = Ticks, time = 116359 True 1
Fn
System Get Time type = Ticks, time = 116468 True 1
Fn
System Get Time type = Ticks, time = 116593 True 1
Fn
System Get Time type = Ticks, time = 117000 True 2
Fn
System Get Time type = Ticks, time = 117140 True 1
Fn
System Get Time type = Ticks, time = 117250 True 1
Fn
System Get Time type = Ticks, time = 117656 True 1
Fn
System Get Time type = Ticks, time = 118062 True 2
Fn
System Get Time type = Ticks, time = 118546 True 1
Fn
System Get Time type = Ticks, time = 119062 True 1
Fn
System Get Time type = Ticks, time = 119296 True 2
Fn
System Get Time type = Ticks, time = 119437 True 1
Fn
System Get Time type = Ticks, time = 119687 True 1
Fn
System Get Time type = Ticks, time = 119953 True 1
Fn
System Get Time type = Ticks, time = 120062 True 1
Fn
System Get Time type = Ticks, time = 120671 True 2
Fn
System Get Time type = Ticks, time = 121000 True 1
Fn
System Get Time type = Ticks, time = 121187 True 1
Fn
System Get Time type = Ticks, time = 122250 True 2
Fn
System Get Time type = Ticks, time = 122609 True 1
Fn
Thread 0x638
117 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 98421 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Get Time type = Ticks, time = 98671 True 1
Fn
System Get Time type = Ticks, time = 98937 True 1
Fn
System Get Time type = Ticks, time = 99312 True 1
Fn
System Get Time type = Ticks, time = 99875 True 2
Fn
System Get Time type = Ticks, time = 100171 True 1
Fn
System Get Time type = Ticks, time = 100468 True 1
Fn
System Get Time type = Ticks, time = 102046 True 2
Fn
System Get Time type = Ticks, time = 102843 True 1
Fn
System Get Time type = Ticks, time = 103265 True 2
Fn
System Get Time type = Ticks, time = 103734 True 1
Fn
System Get Time type = Ticks, time = 104734 True 2
Fn
System Get Time type = Ticks, time = 105156 True 1
Fn
System Get Time type = Ticks, time = 105593 True 1
Fn
System Get Time type = Ticks, time = 105890 True 2
Fn
System Get Time type = Ticks, time = 106078 True 1
Fn
System Get Time type = Ticks, time = 106203 True 1
Fn
System Get Time type = Ticks, time = 106375 True 1
Fn
System Get Time type = Ticks, time = 106562 True 1
Fn
System Get Time type = Ticks, time = 106953 True 2
Fn
System Get Time type = Ticks, time = 107156 True 1
Fn
System Get Time type = Ticks, time = 107343 True 1
Fn
System Get Time type = Ticks, time = 107468 True 1
Fn
System Get Time type = Ticks, time = 107609 True 1
Fn
System Get Time type = Ticks, time = 107765 True 1
Fn
System Get Time type = Ticks, time = 107875 True 1
Fn
System Get Time type = Ticks, time = 107984 True 2
Fn
System Get Time type = Ticks, time = 108093 True 1
Fn
System Get Time type = Ticks, time = 108203 True 1
Fn
System Get Time type = Ticks, time = 108312 True 1
Fn
System Get Time type = Ticks, time = 108421 True 1
Fn
System Get Time type = Ticks, time = 108718 True 1
Fn
System Get Time type = Ticks, time = 108828 True 1
Fn
System Get Time type = Ticks, time = 108968 True 1
Fn
System Get Time type = Ticks, time = 109078 True 2
Fn
System Get Time type = Ticks, time = 109218 True 1
Fn
System Get Time type = Ticks, time = 109328 True 1
Fn
System Get Time type = Ticks, time = 109437 True 1
Fn
System Get Time type = Ticks, time = 109546 True 1
Fn
System Get Time type = Ticks, time = 109656 True 1
Fn
System Get Time type = Ticks, time = 109765 True 1
Fn
System Get Time type = Ticks, time = 109875 True 1
Fn
System Get Time type = Ticks, time = 110000 True 1
Fn
System Get Time type = Ticks, time = 110109 True 2
Fn
System Get Time type = Ticks, time = 110218 True 1
Fn
System Get Time type = Ticks, time = 110328 True 1
Fn
System Get Time type = Ticks, time = 110437 True 1
Fn
System Get Time type = Ticks, time = 110546 True 1
Fn
System Get Time type = Ticks, time = 110656 True 1
Fn
System Get Time type = Ticks, time = 110765 True 1
Fn
System Get Time type = Ticks, time = 110875 True 1
Fn
System Get Time type = Ticks, time = 110984 True 1
Fn
System Get Time type = Ticks, time = 111093 True 1
Fn
System Get Time type = Ticks, time = 111265 True 2
Fn
System Get Time type = Ticks, time = 111390 True 1
Fn
System Get Time type = Ticks, time = 111500 True 1
Fn
System Get Time type = Ticks, time = 111703 True 1
Fn
System Get Time type = Ticks, time = 111828 True 1
Fn
System Get Time type = Ticks, time = 111937 True 1
Fn
System Get Time type = Ticks, time = 112046 True 1
Fn
System Get Time type = Ticks, time = 112156 True 1
Fn
System Get Time type = Ticks, time = 112265 True 1
Fn
System Get Time type = Ticks, time = 112375 True 2
Fn
System Get Time type = Ticks, time = 112500 True 1
Fn
System Get Time type = Ticks, time = 114937 True 2
Fn
System Get Time type = Ticks, time = 115078 True 1
Fn
System Get Time type = Ticks, time = 115187 True 1
Fn
System Get Time type = Ticks, time = 115296 True 1
Fn
System Get Time type = Ticks, time = 115406 True 1
Fn
System Get Time type = Ticks, time = 115531 True 1
Fn
System Get Time type = Ticks, time = 115640 True 1
Fn
System Get Time type = Ticks, time = 115750 True 1
Fn
System Get Time type = Ticks, time = 115875 True 1
Fn
System Get Time type = Ticks, time = 115984 True 2
Fn
System Get Time type = Ticks, time = 116093 True 1
Fn
System Get Time type = Ticks, time = 116359 True 1
Fn
System Get Time type = Ticks, time = 116468 True 1
Fn
System Get Time type = Ticks, time = 116593 True 1
Fn
System Get Time type = Ticks, time = 117000 True 2
Fn
System Get Time type = Ticks, time = 117140 True 1
Fn
System Get Time type = Ticks, time = 117250 True 1
Fn
System Get Time type = Ticks, time = 117656 True 1
Fn
System Get Time type = Ticks, time = 118062 True 2
Fn
System Get Time type = Ticks, time = 118546 True 1
Fn
System Get Time type = Ticks, time = 119062 True 1
Fn
System Get Time type = Ticks, time = 119296 True 2
Fn
System Get Time type = Ticks, time = 119437 True 1
Fn
System Get Time type = Ticks, time = 119687 True 1
Fn
System Get Time type = Ticks, time = 119953 True 1
Fn
System Get Time type = Ticks, time = 120062 True 1
Fn
System Get Time type = Ticks, time = 120671 True 2
Fn
System Get Time type = Ticks, time = 121000 True 1
Fn
System Get Time type = Ticks, time = 121187 True 1
Fn
System Get Time type = Ticks, time = 122250 True 2
Fn
System Get Time type = Ticks, time = 122609 True 1
Fn
Thread 0xc84
3240 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = size, size_out = 129 True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini, type = file_attributes True 1
Fn
File Get Info filename = C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, type = size, size_out = 791421 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Alphabet.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = size, size_out = 27045 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Content.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, type = size, size_out = 111320 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-correct.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = size, size_out = 48936 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-delete.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, type = size, size_out = 46622 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-join.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = size, size_out = 84190 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-US\boxed-split.avi, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\FlickAnimation.avi.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read size = 1048560, size_out = 6320 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6336 True 1
Fn
Data
File Read size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105298.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, type = size, size_out = 2020 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, size = 1048560, size_out = 2020 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105320.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, type = size, size_out = 10508 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, size = 1048560, size_out = 10508 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10512 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105332.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, type = size, size_out = 11584 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, size = 1048560, size_out = 11584 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11600 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105338.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, type = size, size_out = 12380 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, size = 1048560, size_out = 12380 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12384 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105368.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, type = size, size_out = 4624 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, size = 1048560, size_out = 4624 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105380.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, type = size, size_out = 5980 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, size = 1048560, size_out = 5980 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5984 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105386.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, type = size, size_out = 20444 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, size = 1048560, size_out = 20444 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20448 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105410.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, type = size, size_out = 9400 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, size = 1048560, size_out = 9400 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9408 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105412.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, type = size, size_out = 6244 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, size = 1048560, size_out = 6244 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, type = size, size_out = 18728 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, size = 1048560, size_out = 18728 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18736 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105490.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, type = size, size_out = 11720 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 11720 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11728 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 4612 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4624 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105974.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 10060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10064 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106020.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 5812 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5824 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106124.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 14132 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107090.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 27084 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27088 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107130.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 48380 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48384 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107132.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 48388 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48400 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107134.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 17200 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107138.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 5272 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107264.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 5868 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5872 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107266.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 11108 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11120 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107280.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 14132 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107282.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 13436 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13440 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107288.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 16588 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16592 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107364.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 11492 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11504 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107426.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 30336 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30352 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107446.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 4920 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4928 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107450.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 8864 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8880 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105912.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107496.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 7072 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7088 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107658.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 4636 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4640 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107712.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 5492 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5504 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107728.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 3644 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3648 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107742.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 4788 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4800 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107746.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 17867 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17872 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 35419 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35424 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\ado\msado25.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15464 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15472 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151055.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24844 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24848 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152414.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 16432 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16448 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152556.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 10880 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10896 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152560.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 3696 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3712 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152568.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 3368 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3376 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152570.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 10932 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10944 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152590.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 6340 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6352 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152594.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 1268 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152690.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 1348 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152694.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 7320 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7328 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152696.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 1208 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152698.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 8880 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8896 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153093.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 3704 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3712 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153095.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 3008 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3024 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153265.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 20096 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20112 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153273.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 36620 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36624 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153299.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 11396 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11408 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157831.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 18652 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18656 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158071.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 17966 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17968 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0158477.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 29406 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29408 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0160590.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 46484 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46496 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 55554 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 55568 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 36989 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36992 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 29204 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29216 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 28626 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 28640 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183174.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24430 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24432 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183198.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 19274 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19280 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183574.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7304 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7312 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185670.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 20038 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20048 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185774.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14308 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14320 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185842.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8666 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8672 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186346.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 33850 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33856 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186360.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17662 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17664 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186362.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 12292 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12304 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188513.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 5824 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5840 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188519.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 15196 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15200 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188587.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 16030 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16032 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188667.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 29602 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29616 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188669.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 3680 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3696 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195772.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 3004 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3008 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195788.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 4750 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4752 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196060.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 5326 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196110.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 3826 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3840 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196142.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 13702 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13712 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196354.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 42272 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42288 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198113.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 42654 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42656 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198234.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 44552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 44560 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198494.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 50046 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 50048 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199307.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 13756 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13760 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199469.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 12332 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12336 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199609.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 41136 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 41152 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200289.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 10046 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10048 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200521.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 28276 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 28288 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0211981.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 9676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9680 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212601.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 2060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2064 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212751.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 33230 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33232 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215210.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 5618 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5632 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215718.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 42120 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216540.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216612.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 9442 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216612.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9456 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216612.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216612.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 3482 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, size = 3488 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217302.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 58089 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 58096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 7594 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7600 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232395.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 41094 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232395.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 41104 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232395.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232395.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232797.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560 False 1
Fn
Thread 0x970
4080 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Boot\BCD.LOG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = size, size_out = 4662 True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\updaterevokesipolicy.p7b.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\updaterevokesipolicy.p7b, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, type = size, size_out = 623 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcvbs.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc, type = size, size_out = 9804 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\oledbjvs.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc, type = size, size_out = 9975 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\oledbvbs.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 3
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, type = size, size_out = 4964 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, size = 1048560, size_out = 4964 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105376.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, type = size, size_out = 8252 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, size = 1048560, size_out = 8252 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105388.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, type = size, size_out = 31812 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, size = 1048560, size_out = 31812 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31824 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105520.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, type = size, size_out = 17332 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, size = 1048560, size_out = 17332 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105526.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, type = size, size_out = 7384 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, size = 1048560, size_out = 7384 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7392 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105530.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, type = size, size_out = 21548 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, size = 1048560, size_out = 21548 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105588.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, type = size, size_out = 2148 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, size = 1048560, size_out = 2148 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106572.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, type = size, size_out = 3332 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, size = 1048560, size_out = 3332 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106816.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, type = size, size_out = 13784 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, size = 1048560, size_out = 13784 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13792 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106958.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, type = size, size_out = 22300 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, size = 1048560, size_out = 22300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 22304 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107154.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, type = size, size_out = 24908 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, size = 1048560, size_out = 24908 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107158.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, type = size, size_out = 16100 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, size = 1048560, size_out = 16100 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16112 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107182.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, type = size, size_out = 4536 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, size = 1048560, size_out = 4536 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107188.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, type = size, size_out = 10852 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, size = 1048560, size_out = 10852 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10864 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107314.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, type = size, size_out = 11288 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, size = 1048560, size_out = 11288 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11296 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107316.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, type = size, size_out = 6532 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, size = 1048560, size_out = 6532 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107328.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, type = size, size_out = 4244 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, size = 1048560, size_out = 4244 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107342.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, type = size, size_out = 9612 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, size = 1048560, size_out = 9612 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9616 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107468.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, type = size, size_out = 6024 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, size = 1048560, size_out = 6024 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6032 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107480.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, type = size, size_out = 4980 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, size = 1048560, size_out = 4980 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4992 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107482.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, type = size, size_out = 3040 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, size = 1048560, size_out = 3040 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3056 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107484.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, type = size, size_out = 11404 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, size = 1048560, size_out = 11404 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11408 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107512.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, type = size, size_out = 12204 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, size = 1048560, size_out = 12204 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12208 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, type = size, size_out = 14008 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, size = 1048560, size_out = 14008 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14016 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107516.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, type = size, size_out = 7016 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, size = 1048560, size_out = 7016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107724.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, type = size, size_out = 3140 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, size = 1048560, size_out = 3140 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3152 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107734.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, type = size, size_out = 5004 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, size = 1048560, size_out = 5004 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107744.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, type = size, size_out = 8224 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, size = 1048560, size_out = 8224 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107748.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, type = size, size_out = 31850 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, size = 1048560, size_out = 31850 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31856 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, type = size, size_out = 33958 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, size = 1048560, size_out = 33958 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, type = size, size_out = 38237 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, size = 1048560, size_out = 38237 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 38240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, type = size, size_out = 64802 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, size = 1048560, size_out = 64802 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 64816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, type = size, size_out = 18500 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, size = 1048560, size_out = 18500 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18512 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151047.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, type = size, size_out = 13204 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, size = 1048560, size_out = 13204 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151067.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, type = size, size_out = 14132 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, size = 1048560, size_out = 14132 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152430.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, type = size, size_out = 1208 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, size = 1048560, size_out = 1208 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1216 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152702.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, type = size, size_out = 1652 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, size = 1048560, size_out = 1652 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1664 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152704.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, type = size, size_out = 4908 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, size = 1048560, size_out = 4908 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152708.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, type = size, size_out = 4580 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, size = 1048560, size_out = 4580 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4592 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152716.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, type = size, size_out = 1940 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, size = 1048560, size_out = 1940 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1952 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152890.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, type = size, size_out = 11348 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, size = 1048560, size_out = 11348 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11360 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152894.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, type = size, size_out = 33068 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, size = 1048560, size_out = 33068 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33072 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153047.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, type = size, size_out = 7848 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, size = 1048560, size_out = 7848 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7856 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153089.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, type = size, size_out = 17508 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, size = 1048560, size_out = 17508 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17520 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153398.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, type = size, size_out = 34256 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, size = 1048560, size_out = 34256 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 34272 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153508.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, type = size, size_out = 12752 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, size = 1048560, size_out = 12752 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12768 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153514.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, type = size, size_out = 7432 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, size = 1048560, size_out = 7432 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7440 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153516.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, type = size, size_out = 12696 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, size = 1048560, size_out = 12696 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12704 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172193.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, type = size, size_out = 5864 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, size = 1048560, size_out = 5864 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5872 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174315.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, type = size, size_out = 9736 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, size = 1048560, size_out = 9736 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9744 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174635.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, type = size, size_out = 5100 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, size = 1048560, size_out = 5100 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5104 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174639.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, type = size, size_out = 26531 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, size = 1048560, size_out = 26531 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, type = size, size_out = 24034 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, size = 1048560, size_out = 24034 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24048 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, type = size, size_out = 23338 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, size = 1048560, size_out = 23338 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178632.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, type = size, size_out = 32038 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 32038 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 32048 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 27096 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27104 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185776.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 25312 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 25328 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185778.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 59734 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 59744 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185780.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 39330 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 39344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185786.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 18212 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18224 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0186364.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 6596 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6608 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187647.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 5376 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5392 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187815.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 11644 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187817.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 10352 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10368 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187819.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4696 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4704 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187881.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2100 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2112 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187883.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5620 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5632 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187893.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3472 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3488 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187895.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5000 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5008 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187921.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10716 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10720 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188511.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7332 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7344 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195248.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4534 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4544 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195254.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8314 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195260.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 29432 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29440 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195320.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 21328 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21344 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195342.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 18622 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18624 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0195428.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 54964 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 54976 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198102.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 40300 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 40304 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198377.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 29006 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29008 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199279.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16688 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199429.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5072 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199465.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10164 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10176 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199483.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5312 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200183.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 31302 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31312 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200273.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3894 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3904 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200611.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 3840 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3856 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213449.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 31926 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31936 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214934.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 44794 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 44800 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0214948.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11628 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11632 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215070.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9290 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9296 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215709.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 21620 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21632 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24796 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24800 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216570.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216570.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217872.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7336 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217872.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7344 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217872.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217872.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228823.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 26022 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228823.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26032 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228823.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228823.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4198 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4208 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230558.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232795.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14346 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232795.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14352 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232795.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232795.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232803.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 False 1
Fn
Thread 0x964
3361 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 3
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml, type = size, size_out = 2580 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnor.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml, type = size, size_out = 2600 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsplk.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml, type = size, size_out = 2246 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptb.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml, type = size, size_out = 2240 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsptg.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml, type = size, size_out = 2644 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrom.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml, type = size, size_out = 2542 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsrus.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml, type = size, size_out = 2568 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipssrb.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, type = size, size_out = 630 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\msadc\adcjavas.inc, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2900 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2912 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105336.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, type = size, size_out = 8860 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, size = 1048560, size_out = 8860 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8864 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105360.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, type = size, size_out = 4964 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, size = 1048560, size_out = 4964 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4976 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105378.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, type = size, size_out = 4944 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, size = 1048560, size_out = 4944 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105390.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, type = size, size_out = 11012 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, size = 1048560, size_out = 11012 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105396.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, type = size, size_out = 3328 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, size = 1048560, size_out = 3328 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105398.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, type = size, size_out = 8680 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, size = 1048560, size_out = 8680 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8688 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105600.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, type = size, size_out = 10364 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, size = 1048560, size_out = 10364 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10368 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105638.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, type = size, size_out = 13808 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, size = 1048560, size_out = 13808 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13824 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105710.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, type = size, size_out = 8240 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, size = 1048560, size_out = 8240 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105846.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, type = size, size_out = 3020 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, size = 1048560, size_out = 3020 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3024 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107024.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, type = size, size_out = 7632 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, size = 1048560, size_out = 7632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107026.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, type = size, size_out = 9048 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, size = 1048560, size_out = 9048 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9056 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107042.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, type = size, size_out = 9968 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, size = 1048560, size_out = 9968 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9984 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107192.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, type = size, size_out = 20212 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, size = 1048560, size_out = 20212 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20224 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107254.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, type = size, size_out = 8552 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, size = 1048560, size_out = 8552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8560 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107258.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, type = size, size_out = 7996 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, size = 1048560, size_out = 7996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107262.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, type = size, size_out = 5076 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, size = 1048560, size_out = 5076 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5088 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107344.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, type = size, size_out = 23672 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, size = 1048560, size_out = 23672 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23680 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107350.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, type = size, size_out = 7964 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, size = 1048560, size_out = 7964 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107358.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, type = size, size_out = 8000 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, size = 1048560, size_out = 8000 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8016 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107488.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, type = size, size_out = 16468 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, size = 1048560, size_out = 16468 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16480 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107490.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, type = size, size_out = 6860 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, size = 1048560, size_out = 6860 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6864 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107492.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, type = size, size_out = 6424 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, size = 1048560, size_out = 6424 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6432 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107494.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, type = size, size_out = 7948 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, size = 1048560, size_out = 7948 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7952 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107526.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, type = size, size_out = 6792 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, size = 1048560, size_out = 6792 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107528.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, type = size, size_out = 26768 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, size = 1048560, size_out = 26768 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26784 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107544.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, type = size, size_out = 4716 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 4716 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 16710 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16720 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0136865.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 40231 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 40240 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 33657 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33664 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 36820 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36832 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 39542 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 39552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 46508 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46512 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 27393 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27408 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 46404 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46416 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107750.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150150.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, size = 1048560, size_out = 4356 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4368 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151041.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10640 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151063.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13336 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13344 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151073.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16492 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152432.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 11340 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11344 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152436.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16052 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16064 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151045.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9768 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9776 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152600.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6276 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6288 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152602.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16632 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16640 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152606.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 12436 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12448 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152608.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7020 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7024 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152722.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7876 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7888 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152876.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14888 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14896 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152878.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9072 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9088 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152882.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6956 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6960 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152884.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 30800 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153302.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 38488 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 38496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153305.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 15448 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153307.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16952 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16960 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153313.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 20906 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20912 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0168644.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14472 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14480 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171685.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6888 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6896 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0171847.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7448 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7456 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172035.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7028 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7040 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0172067.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 15150 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15152 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182898.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 7822 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7824 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182902.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 16082 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182946.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 29788 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29792 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0183172.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 30522 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30528 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185806.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 35726 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185818.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 7796 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7808 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185828.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 8578 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8592 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185834.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7572 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7584 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187849.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8732 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8736 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187851.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2732 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2736 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187859.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9108 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9120 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187861.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10820 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10832 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187863.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13162 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13168 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0188679.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6912 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6928 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196358.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5708 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5712 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0196364.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 40230 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 40240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197979.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 26252 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26256 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0197983.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 41906 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 41920 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198226.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 49676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 49680 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198447.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 26154 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199423.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10776 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10784 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199473.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7180 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7184 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200163.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8064 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200189.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 20232 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200377.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 21400 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21408 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200383.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 6158 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212299.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7498 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7504 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212953.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213243.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 2652 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213243.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2656 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213243.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0213243.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216874.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 39738 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216874.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 39744 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216874.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216874.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228959.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 37260 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228959.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 37264 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228959.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0228959.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232171.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 13098 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232171.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13104 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232171.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
Thread 0xa94
3531 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 3
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat, type = size, size_out = 46624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrcommonlm.dat, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat, type = size, size_out = 498624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrenclm.dat, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat, type = size, size_out = 1100592 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrlatinlm.dat, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, type = size, size_out = 2515696 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusalm.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, type = size, size_out = 3380096 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\hwrusash.dat.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, type = size, size_out = 2418 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsar.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml, type = size, size_out = 2592 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipscat.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnld.xml, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnld.xml.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ipsnld.xml, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read size = 1048560, size_out = 4320 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4336 True 1
Fn
Data
File Read size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105306.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, type = size, size_out = 7992 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, size = 1048560, size_out = 7992 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8000 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105328.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, type = size, size_out = 17060 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, size = 1048560, size_out = 17060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17072 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105348.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, type = size, size_out = 5880 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, size = 1048560, size_out = 5880 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5888 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105384.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, type = size, size_out = 5156 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, size = 1048560, size_out = 5156 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5168 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105496.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, type = size, size_out = 5472 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, size = 1048560, size_out = 5472 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5488 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105502.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, type = size, size_out = 4148 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, size = 1048560, size_out = 4148 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4160 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105504.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, type = size, size_out = 2912 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, size = 1048560, size_out = 2912 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2928 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105506.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, type = size, size_out = 23548 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, size = 1048560, size_out = 23548 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106146.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, type = size, size_out = 11900 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, size = 1048560, size_out = 11900 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 11904 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106208.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, type = size, size_out = 19600 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, size = 1048560, size_out = 19600 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19616 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0106222.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, type = size, size_out = 14996 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, size = 1048560, size_out = 14996 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15008 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107146.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, type = size, size_out = 20136 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, size = 1048560, size_out = 20136 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107148.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, type = size, size_out = 13456 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, size = 1048560, size_out = 13456 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13472 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107150.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, type = size, size_out = 22532 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, size = 1048560, size_out = 22532 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 22544 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107152.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, type = size, size_out = 12308 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, size = 1048560, size_out = 12308 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12320 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107290.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, type = size, size_out = 2460 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, size = 1048560, size_out = 2460 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2464 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107300.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, type = size, size_out = 4136 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, size = 1048560, size_out = 4136 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4144 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107302.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, type = size, size_out = 15888 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, size = 1048560, size_out = 15888 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15904 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107308.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, type = size, size_out = 21216 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, size = 1048560, size_out = 21216 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21232 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107452.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, type = size, size_out = 3724 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, size = 1048560, size_out = 3724 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3728 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107456.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, type = size, size_out = 3568 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, size = 1048560, size_out = 3568 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3584 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107458.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, type = size, size_out = 4200 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, size = 1048560, size_out = 4200 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4208 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107500.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, type = size, size_out = 10836 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, size = 1048560, size_out = 10836 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10848 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107502.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, type = size, size_out = 4808 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, size = 1048560, size_out = 4808 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107708.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, type = size, size_out = 3800 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, size = 1048560, size_out = 3800 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3808 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107718.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, type = size, size_out = 8260 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, size = 1048560, size_out = 8260 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8272 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107722.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, type = size, size_out = 3060 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, size = 1048560, size_out = 3060 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3072 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107730.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, type = size, size_out = 61633 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, size = 1048560, size_out = 61633 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 61648 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, type = size, size_out = 49238 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, size = 1048560, size_out = 49238 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 49248 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, type = size, size_out = 21125 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, size = 1048560, size_out = 21125 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21136 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, type = size, size_out = 36792 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, size = 1048560, size_out = 36792 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36800 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, type = size, size_out = 43674 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, size = 1048560, size_out = 43674 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 43680 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, type = size, size_out = 67540 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, size = 1048560, size_out = 67540 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 67552 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, type = size, size_out = 8494 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, size = 1048560, size_out = 8494 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8496 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0150861.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, type = size, size_out = 6752 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, size = 1048560, size_out = 6752 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6768 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151061.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 10752 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10768 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0151581.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5960 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5968 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152610.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9604 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9616 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152622.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 26248 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26256 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152626.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 30812 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 30816 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152628.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152558.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 34676 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 34688 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152688.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 10668 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 10672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152892.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 4496 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4512 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0152898.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1912 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1920 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153087.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 8136 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8144 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153091.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 12528 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12544 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0153518.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 1376 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1392 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0156537.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 46702 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46704 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157167.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 21716 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157177.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 17912 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17920 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0157191.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24982 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24992 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 46461 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 46464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175361.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 14552 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14560 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 45358 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 45360 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 35340 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35344 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 32110 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 32112 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16615 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16624 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24392 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24400 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182888.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 20662 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185790.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 25868 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 25872 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185796.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 33824 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33840 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185798.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 24238 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0185800.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7500 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7504 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187825.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 12352 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12368 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187829.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 9344 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 9360 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187835.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 16354 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16368 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187837.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 5372 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5376 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187839.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 7116 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 7120 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0187847.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 33948 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 33952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198016.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 23726 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198020.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 34912 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 34928 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198021.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 26148 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198022.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 15566 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15568 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198025.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 28572 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 28576 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198372.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 57722 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 57728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0198712.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 31822 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31824 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199303.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 5252 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5264 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0199475.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 8196 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8208 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200151.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 19466 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19472 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200279.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 13934 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 13936 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0200467.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 42254 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42256 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 6554 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 6560 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0212685.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 8016 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8032 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215076.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 17826 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17840 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0215710.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 42883 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 42896 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 8006 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 8016 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216600.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216600.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 5252 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5264 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217262.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0217262.WMF True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 35542 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35552 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG True 1
Fn
File Create filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232393.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 27586 True 1
Fn
Data
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232393.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27600 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0232393.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
Thread 0x908
249 0
»
Category Operation Information Success Count Logfile
Thread 0xa8c
2498 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Boot\BCD, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\BCD.LOG1, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG1, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\BCD.LOG2, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\BCD.LOG2, type = size, size_out = 0 True 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = size, size_out = 77664 True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bg-BG\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bg-BG\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = size, size_out = 95648 True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootspaces.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootspaces.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = size, size_out = 99744 True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\bootvhd.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\bootvhd.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\cs-CZ\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui, type = size, size_out = 76632 True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\cs-CZ\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\cs-CZ\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Boot\Fonts\chs_boot.ttf, destination_filename = C:\Boot\Fonts\chs_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\cht_boot.ttf, destination_filename = C:\Boot\Fonts\cht_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\jpn_boot.ttf, destination_filename = C:\Boot\Fonts\jpn_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Boot\Fonts\kor_boot.ttf, destination_filename = C:\Boot\Fonts\kor_boot.ttf.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read size = 1048560, size_out = 21184 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21200 True 1
Fn
Data
File Read size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 272 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, type = size, size_out = 19136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, size = 1048560, size_out = 19136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19152 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll, type = size, size_out = 162880 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ApiClient.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll, type = size, size_out = 656088 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVCatalog.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe, type = size, size_out = 2054872 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786698 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, type = size, size_out = 902328 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, size = 1048560, size_out = 902328 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 902336 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, type = size, size_out = 390320 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, size = 1048560, size_out = 390320 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 390336 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, type = size, size_out = 88752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\vcruntime140.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\ar-SA\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\mip.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mip.exe, type = size, size_out = 1540608 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mip.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mip.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\mip.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, type = size, size_out = 590523 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, size = 1048560, size_out = 590523 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, size = 590528 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.id-B4197730.[idecryptyourdata@cock.li].bat, size = 260 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, type = size, size_out = 855376 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, size = 1048560, size_out = 855376 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 855392 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, type = size, size_out = 168064 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, size = 1048560, size_out = 168064 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 168080 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, type = size, size_out = 22680 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, size = 1048560, size_out = 22680 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, size = 22688 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, type = size, size_out = 159808 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, size = 1048560, size_out = 159808 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 159824 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\dcpr.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 1156672 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, size = 1048560, size_out = 108112 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 108128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, type = size, size_out = 455744 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, size = 1048560, size_out = 455744 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 455760 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, type = size, size_out = 158272 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 158272 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 158288 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\hprof.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, type = size, size_out = 80448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, size = 1048560, size_out = 80448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 80464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, type = size, size_out = 69184 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, size = 1048560, size_out = 69184 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 69200 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, type = size, size_out = 319552 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, size = 1048560, size_out = 319552 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 319568 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, type = size, size_out = 15424 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, size = 1048560, size_out = 15424 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15440 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\JAWTAccessBridge-64.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, type = size, size_out = 296000 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, size = 1048560, size_out = 296000 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 296016 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, type = size, size_out = 20032 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, size = 1048560, size_out = 20032 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20048 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2native.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, type = size, size_out = 18496 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, size = 1048560, size_out = 18496 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18512 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jsdt.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, type = size, size_out = 829264 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, size = 1048560, size_out = 829264 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 829280 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, type = size, size_out = 96832 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, size = 1048560, size_out = 96832 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 96848 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\net.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, type = size, size_out = 60480 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, size = 1048560, size_out = 60480 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 60496 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\nio.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, type = size, size_out = 234560 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, size = 1048560, size_out = 234560 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234576 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, type = size, size_out = 57408 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, size = 1048560, size_out = 57408 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 57424 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_common.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\servertool.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, type = size, size_out = 571968 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, size = 1048560, size_out = 571968 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 571984 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, type = size, size_out = 31808 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, size = 1048560, size_out = 31808 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31824 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\sunmscapi.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, type = size, size_out = 255040 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, size = 1048560, size_out = 255040 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 255056 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\t2k.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, type = size, size_out = 192576 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, size = 1048560, size_out = 192576 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 192592 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\wsdetect.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, type = size, size_out = 3244 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, size = 1048560, size_out = 3244 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3248 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\COPYRIGHT True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, type = size, size_out = 51236 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, size = 1048560, size_out = 51236 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 51248 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, type = size, size_out = 1044 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, size = 1048560, size_out = 1044 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1056 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, type = size, size_out = 3144 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, size = 1048560, size_out = 3144 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3152 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, type = size, size_out = 5548 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, size = 1048560, size_out = 5548 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 5552 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 260 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties, type = size, size_out = 3409 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties, size = 1048560 False 1
Fn
Thread 0xa90
2621 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\$WINRE_BACKUP_PARTITION.MARKER, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\$WINRE_BACKUP_PARTITION.MARKER, type = size, size_out = 0 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
File Create filename = C:\Boot\fr-FR\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\fr-FR\memtest.exe.mui, type = size, size_out = 45984 True 1
Fn
File Get Info filename = C:\Boot\fr-FR\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\fr-FR\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\fr-FR\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\hr-HR\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\hr-HR\bootmgr.exe.mui, type = size, size_out = 76640 True 1
Fn
File Get Info filename = C:\Boot\hr-HR\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\hr-HR\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\hr-HR\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\hu-HU\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\hu-HU\bootmgr.exe.mui, type = size, size_out = 78688 True 1
Fn
File Get Info filename = C:\Boot\hu-HU\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\hu-HU\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\hu-HU\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\hu-HU\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\hu-HU\memtest.exe.mui, type = size, size_out = 45976 True 1
Fn
File Get Info filename = C:\Boot\hu-HU\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\hu-HU\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\hu-HU\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\it-IT\bootmgr.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\it-IT\bootmgr.exe.mui, type = size, size_out = 77144 True 1
Fn
File Get Info filename = C:\Boot\it-IT\bootmgr.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\it-IT\bootmgr.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\it-IT\bootmgr.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Boot\it-IT\memtest.exe.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Boot\it-IT\memtest.exe.mui, type = size, size_out = 45472 True 1
Fn
File Get Info filename = C:\Boot\it-IT\memtest.exe.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Boot\it-IT\memtest.exe.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Boot\it-IT\memtest.exe.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\bootmgr, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Boot\it-IT\memtest.exe.mui, size = 1048560, size_out = 19136 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19152 True 1
Fn
Data
File Read filename = C:\Boot\it-IT\memtest.exe.mui, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 276 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll, type = size, size_out = 473760 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll, type = size, size_out = 210648 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll, type = size, size_out = 1402584 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, type = size, size_out = 1761448 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786714 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, type = size, size_out = 332968 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, size = 1048560, size_out = 332968 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 332976 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll, type = size, size_out = 3144288 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll, type = size, size_out = 4677216 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, type = size, size_out = 996568 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, size = 1048560, size_out = 996568 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 996576 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, type = size, size_out = 2776664 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll, type = size, size_out = 1053784 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\StreamServer.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll, type = size, size_out = 982720 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll, size = 1048560, size_out = 982720 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 982736 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll, type = size, size_out = 6368768 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\mraut.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, type = size, size_out = 244296 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, size = 1048560, size_out = 244296 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244304 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, type = size, size_out = 990032 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, size = 1048560, size_out = 990032 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 990048 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, type = size, size_out = 17048 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, size = 1048560, size_out = 17048 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, size = 17056 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb True 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, type = size, size_out = 17920 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\en-US\msader15.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msader15.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll, type = size, size_out = 2560 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msader15.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msader15.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado15.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll, type = size, size_out = 1233920 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado15.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado15.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado20.tlb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado20.tlb, type = size, size_out = 50688 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado20.tlb, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado20.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado20.tlb, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado21.tlb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado21.tlb, type = size, size_out = 53760 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado21.tlb, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado21.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado21.tlb, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado25.tlb, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado25.tlb, type = size, size_out = 69632 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado25.tlb, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\ado\msado25.tlb.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\ado\msado25.tlb, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 75776 True 1
Fn
Data
File Write filename = C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 75792 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0107514.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Internet Explorer\spray-roman.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Internet Explorer\spray-roman.exe True 1
Fn
File Create filename = C:\Program Files\Internet Explorer\sqmapi.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Internet Explorer\sqmapi.dll, type = size, size_out = 49688 True 1
Fn
File Get Info filename = C:\Program Files\Internet Explorer\sqmapi.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Internet Explorer\sqmapi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Internet Explorer\sqmapi.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, type = size, size_out = 1516608 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, size = 1048560, size_out = 468048 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 468064 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\awt.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, type = size, size_out = 16960 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, size = 1048560, size_out = 16960 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16976 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\bci.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, type = size, size_out = 29760 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, size = 1048560, size_out = 29760 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29776 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_shmem.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, type = size, size_out = 136256 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, size = 1048560, size_out = 136256 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 136272 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\eula.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, type = size, size_out = 123456 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, size = 1048560, size_out = 123456 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 123472 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\instrument.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, type = size, size_out = 19008 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, size = 1048560, size_out = 19008 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19024 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pcsc.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, type = size, size_out = 21056 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, size = 1048560, size_out = 21056 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 21072 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jaas_nt.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, type = size, size_out = 142400 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, size = 1048560, size_out = 142400 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 142416 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\JavaAccessBridge-64.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, type = size, size_out = 206912 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, size = 1048560, size_out = 206912 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 206928 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, type = size, size_out = 29760 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, size = 1048560, size_out = 29760 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 29776 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\java_crw_demo.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, type = size, size_out = 15936 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, size = 1048560, size_out = 15936 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, type = size, size_out = 112192 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, size = 1048560, size_out = 112192 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 112208 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2launcher.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, type = size, size_out = 185920 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, size = 1048560, size_out = 185920 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 185936 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jpeg.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, type = size, size_out = 31296 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, size = 1048560, size_out = 31296 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 31312 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jsoundds.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, type = size, size_out = 233536 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, size = 1048560, size_out = 233536 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 233552 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\lcms.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, type = size, size_out = 653888 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, size = 1048560, size_out = 653888 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 653904 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, type = size, size_out = 19008 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, size = 1048560, size_out = 19008 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19024 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\npt.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, type = size, size_out = 829264 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 829264 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 829280 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll, type = size, size_out = 8809536 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786682 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, type = size, size_out = 79936 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, size = 1048560, size_out = 79936 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 79952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, type = size, size_out = 77888 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, size = 1048560, size_out = 77888 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 77904 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\zip.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar, type = size, size_out = 3036922 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar, destination_filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786692 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, type = size, size_out = 3223 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, size = 1048560, size_out = 3223 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3232 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties, type = size, size_out = 6349 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties, size = 1048560 False 1
Fn
Thread 0xc4c
2703 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, type = size, size_out = 27840 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, size = 1048560, size_out = 27840 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 27856 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 272 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, type = size, size_out = 70848 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, size = 1048560, size_out = 70848 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 70864 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, type = size, size_out = 23232 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, size = 1048560, size_out = 23232 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 23248 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll, type = size, size_out = 307416 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVFileSystemMetadata.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll, type = size, size_out = 2118360 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll, type = size, size_out = 468696 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, type = size, size_out = 396960 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, size = 1048560, size_out = 396960 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 396976 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, type = size, size_out = 263896 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, size = 1048560, size_out = 263896 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 263904 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, type = size, size_out = 820416 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, size = 1048560, size_out = 820416 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 820432 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll, type = size, size_out = 1208928 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, type = size, size_out = 102 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, size = 1048560, size_out = 102 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat, size = 112 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, type = size, size_out = 102 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, size = 1048560, size_out = 102 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat, size = 112 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, type = size, size_out = 1093248 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, size = 1048560, size_out = 44688 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 44704 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 252 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\bg-BG\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui, type = size, size_out = 9728 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\cs-CZ\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui, type = size, size_out = 10240 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\da-DK\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\de-DE\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui, type = size, size_out = 10752 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\el-GR\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui, type = size, size_out = 9728 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\en-GB\tipresx.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\InkObj.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\InkObj.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\micaut.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\micaut.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ink\tabskb.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ink\tabskb.dll.id-B4197730.[idecryptyourdata@cock.li].bat False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 363728 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, size = 363744 True 1
Fn
Data
File Read filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0105414.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, type = size, size_out = 18624 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, size = 1048560, size_out = 18624 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 18640 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 260 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig.companion.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll, type = size, size_out = 987136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VGX\VGX.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, type = size, size_out = 12448 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, size = 1048560, size_out = 12448 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 12464 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, type = size, size_out = 20608 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, size = 1048560, size_out = 20608 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 20624 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOLoaderUI.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, type = size, size_out = 100488 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, size = 1048560, size_out = 100488 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 100496 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOInstaller.exe True 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui, type = size, size_out = 48128 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\oledb32r.dll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui, type = size, size_out = 44032 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqloledb.rll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui, type = size, size_out = 18432 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\en-US\sqlxmlx.rll.mui, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdaosp.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaosp.dll, type = size, size_out = 99840 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaosp.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaosp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdaosp.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdaps.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaps.dll, type = size, size_out = 376320 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaps.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdaps.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdaps.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, type = size, size_out = 698368 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, size = 1048560, size_out = 452 True 1
Fn
Data
File Write filename = C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat, size = 464 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\System\Ole DB\msdasql.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Internet Explorer\SIGNUP\install.ins.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Internet Explorer\SIGNUP\install.ins True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, type = size, size_out = 587840 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, size = 1048560, size_out = 587840 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, size = 587856 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, type = size, size_out = 24640 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, size = 1048560, size_out = 24640 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24656 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\dt_socket.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, type = size, size_out = 274496 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, size = 1048560, size_out = 274496 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274512 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, type = size, size_out = 186944 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, size = 1048560, size_out = 186944 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 186960 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\fxplugins.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, type = size, size_out = 619584 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, size = 1048560, size_out = 619584 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 619600 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 248 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, type = size, size_out = 15936 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, size = 1048560, size_out = 15936 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, type = size, size_out = 159808 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, size = 1048560, size_out = 159808 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 159824 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\java.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, type = size, size_out = 206912 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, size = 1048560, size_out = 206912 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 206928 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\java.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, type = size, size_out = 538176 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, size = 1048560, size_out = 538176 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 538192 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, type = size, size_out = 201792 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, size = 1048560, size_out = 201792 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 201808 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jdwp.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, type = size, size_out = 139840 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, size = 1048560, size_out = 139840 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 139856 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxmedia.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll, type = size, size_out = 41503296 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786694 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, type = size, size_out = 963232 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 963232 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 963248 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, type = size, size_out = 70208 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, size = 1048560, size_out = 70208 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 70224 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, type = size, size_out = 135744 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, size = 1048560, size_out = 135744 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 135760 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\sunec.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, type = size, size_out = 49216 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, size = 1048560, size_out = 49216 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 49232 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\verify.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, type = size, size_out = 110144 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, size = 1048560, size_out = 110144 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 110160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 264 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\WindowsAccessBridge-64.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, type = size, size_out = 149 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, size = 1048560, size_out = 149 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 260 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, type = size, size_out = 634 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, size = 1048560, size_out = 634 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat, size = 640 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties, type = size, size_out = 1378 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties, size = 1048560, size_out = 1378 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1392 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 252 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0230553.WMF.id-B4197730.[idecryptyourdata@cock.li].bat, type = size, size_out = 632 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, size = 1048560, size_out = 632 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 640 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, type = size, size_out = 274474 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, size = 1048560, size_out = 274474 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274480 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, type = size, size_out = 4122 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, size = 1048560, size_out = 4122 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat, size = 4128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\currency.data True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties, type = size, size_out = 2860 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, size = 1048560, size_out = 2860 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 2864 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties, type = size, size_out = 3600 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties, size = 1048560 False 1
Fn
Thread 0x90c
2598 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77050000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = Wow64DisableWow64FsRedirection, address_out = 0x77066b30 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 2
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, type = size, size_out = 26816 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, size = 1048560, size_out = 26816 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26832 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 282 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, type = size, size_out = 19648 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, size = 1048560, size_out = 19648 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 19664 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 278 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, type = size, size_out = 24768 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, size = 1048560, size_out = 24768 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24784 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 274 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, type = size, size_out = 24768 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, size = 1048560, size_out = 24768 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24784 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 276 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll, type = size, size_out = 2285736 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll, type = size, size_out = 567512 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll, type = size, size_out = 1231576 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll, type = size, size_out = 947928 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll, type = size, size_out = 1295576 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, type = size, size_out = 512216 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, size = 1048560, size_out = 512216 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 512224 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 246 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, type = size, size_out = 358616 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, size = 1048560, size_out = 358616 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 358624 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll, type = size, size_out = 3177152 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uires.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll, type = size, size_out = 9330784 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll.id-B4197730.[idecryptyourdata@cock.li].bat, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\mso40uiwin32client.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, type = size, size_out = 61024 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, size = 1048560, size_out = 61024 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 61040 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 250 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msointl30.en-us.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll, type = size, size_out = 660136 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp120.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll, type = size, size_out = 635040 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcp140.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll, type = size, size_out = 963240 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\msvcr120.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, type = size, size_out = 5967976 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe, destination_filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786706 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll, type = size, size_out = 503808 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\Microsoft.Ink.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll, type = size, size_out = 51200 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\ink\mshwgst.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, type = size, size_out = 1475160 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, size = 1048560, size_out = 1048560 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1048560 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, size = 1048560, size_out = 426600 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 426608 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, type = size, size_out = 367216 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, size = 1048560, size_out = 367216 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 367232 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, type = size, size_out = 48872 True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, size = 1048560, size_out = 48872 True 1
Fn
Data
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 48880 True 1
Fn
Data
File Read filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 258 True 1
Fn
Data
File Delete filename = C:\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOMessageProvider.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, type = size, size_out = 86080 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, size = 1048560, size_out = 86080 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 86096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, type = size, size_out = 1026112 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, size = 1048560, size_out = 1026112 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 1026128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, type = size, size_out = 265792 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, size = 1048560, size_out = 265792 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 265808 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\glass.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, type = size, size_out = 63552 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, size = 1048560, size_out = 63552 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 63568 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\j2pkcs11.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, type = size, size_out = 34368 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, size = 1048560, size_out = 34368 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 34384 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, type = size, size_out = 187392 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, size = 1048560, size_out = 187392 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat, size = 187408 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, type = size, size_out = 128064 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, size = 1048560, size_out = 128064 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 128080 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\javafx_iio.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, type = size, size_out = 14400 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, size = 1048560, size_out = 14400 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 14416 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jawt.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, type = size, size_out = 26688 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, size = 1048560, size_out = 26688 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 26704 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jfr.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, type = size, size_out = 174656 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, size = 1048560, size_out = 174656 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 174672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 226 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jli.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, type = size, size_out = 235584 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, size = 1048560, size_out = 235584 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 235600 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, type = size, size_out = 35392 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, size = 1048560, size_out = 35392 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 35408 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 232 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\jsound.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, type = size, size_out = 220736 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, size = 1048560, size_out = 220736 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 220752 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\kcms.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 234 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\klist.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, type = size, size_out = 36928 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, size = 1048560, size_out = 36928 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 36944 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 240 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\management.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, type = size, size_out = 660128 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, size = 1048560, size_out = 660128 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 660144 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, type = size, size_out = 130624 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, size = 1048560, size_out = 130624 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 130640 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_d3d.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, type = size, size_out = 97856 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, size = 1048560, size_out = 97856 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 97872 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\prism_sw.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, type = size, size_out = 15424 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, size = 1048560, size_out = 15424 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15440 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 236 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\resource.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, type = size, size_out = 15936 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, size = 1048560, size_out = 15936 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 15952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 228 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, type = size, size_out = 16448 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, size = 1048560, size_out = 16448 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 16464 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 242 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa, type = size, size_out = 18677760 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Move source_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa, destination_filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE, GENERIC_READ True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144, size_out = 262144 True 3
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat, size = 786690 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.id-B4197730.[idecryptyourdata@cock.li].bat, size = 262144 True 3
Fn
Data
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, type = size, size_out = 204864 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, size = 1048560, size_out = 204864 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 204880 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\splashscreen.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, type = size, size_out = 197184 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, size = 1048560, size_out = 197184 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 197200 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe.id-B4197730.[idecryptyourdata@cock.li].bat, size = 238 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, type = size, size_out = 24128 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, size = 1048560, size_out = 24128 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 24144 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll.id-B4197730.[idecryptyourdata@cock.li].bat, size = 244 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\bin\w2k_lsa_auth.dll True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, type = size, size_out = 84355 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, size = 1048560, size_out = 84355 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat, size = 84368 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist.id-B4197730.[idecryptyourdata@cock.li].bat, size = 230 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\classlist True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, type = size, size_out = 3306 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, size = 1048560, size_out = 3306 True 1
Fn
Data
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 3312 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties, size = 1048560, size_out = 0 True 1
Fn
File Write filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.id-B4197730.[idecryptyourdata@cock.li].bat, size = 256 True 1
Fn
Data
File Delete filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties, type = size, size_out = 5712 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties.id-B4197730.[idecryptyourdata@cock.li].bat, type = file_attributes False 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties, desired_access = GENERIC_WRITE, GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties.id-B4197730.[idecryptyourdata@cock.li].bat, desired_access = GENERIC_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties, size = 1048560 False 1
Fn
Thread 0x904
249 0
»
Category Operation Information Success Count Logfile
Process #13: cmd.exe
284 0
»
Information Value
ID #13
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:57, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:10
OS Process Information
»
Information Value
PID 0xc40
Parent PID 0x2a8 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C48
0x 4CC
Threads
Thread 0xc48
284 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x7ff695310000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff8c81c0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\WINDOWS\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
System Get Info type = Operating System True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 38 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 52 True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff8c81c0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7ff8c81de830 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x7ff8c81de300 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x7ff8c5880a40 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 24 True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\WINDOWS\system32\mode.com, os_pid = 0x500, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Load module_name = NTDLL.DLL, base_address = 0x7ff8c85b0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ntdll.dll, function = NtQueryInformationProcess, address_out = 0x7ff8c86556b0 True 1
Fn
Process Get Info type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory Read process_name = C:\WINDOWS\system32\mode.com, address = 357413429248, size = 1952 True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 36 True 1
Fn
Data
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process Create process_name = C:\WINDOWS\system32\vssadmin.exe, os_pid = 0x4a0, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Process Get Info type = PROCESS_BASIC_INFORMATION True 1
Fn
Memory Read process_name = C:\WINDOWS\system32\vssadmin.exe, address = 1062815592448, size = 1952 True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000002 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 True 1
Fn
Data
Environment Get Environment String name = PROMPT, result_out = $P$G True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 20 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = STD_INPUT_HANDLE, size = 1, size_out = 1 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 5 True 1
Fn
Data
Process #15: cmd.exe
60 0
»
Information Value
ID #15
File Name c:\windows\system32\cmd.exe
Command Line "C:\WINDOWS\system32\cmd.exe"
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:02:59, Reason: Child Process
Unmonitor End Time: 00:03:06, Reason: Self Terminated
Monitor Duration 00:00:07
OS Process Information
»
Information Value
PID 0xbb0
Parent PID 0xe24 (c:\programdata\microsoft\windows\start menu\programs\startup\hgaibc.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level Medium
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 9C8
0x 4F8
Threads
Thread 0x9c8
60 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x7ff695310000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x7ff8c81c0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x7ff8c81da990 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 4, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\WINDOWS\system32\cmd.exe, size = 32743 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\ProgramData\Oracle\Java\javapath;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\Users\FD1HVy\AppData\Local\Microsoft\WindowsApps; True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\WINDOWS\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\WINDOWS\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
System Get Info type = Operating System True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 38 False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 2 False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Write filename = STD_ERROR_HANDLE, size = 51 False 1
Fn
Process #17: mode.com
0 0
»
Information Value
ID #17
File Name c:\windows\system32\mode.com
Command Line mode con cp select=1251
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:03:06, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x500
Parent PID 0xc40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 4A4
0x CF8
Process #18: vssadmin.exe
0 0
»
Information Value
ID #18
File Name c:\windows\system32\vssadmin.exe
Command Line vssadmin delete shadows /all /quiet
Initial Working Directory C:\WINDOWS\system32\
Monitor Start Time: 00:03:07, Reason: Child Process
Unmonitor End Time: 00:03:08, Reason: Self Terminated
Monitor Duration 00:00:01
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0x4a0
Parent PID 0xc40 (c:\windows\system32\cmd.exe)
Bitness 64-bit
Is Created or Modified Executable False
Integrity Level High (Elevated)
Username NQDPDE\FD1HVy
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x 36C
0x 3A4
0x 478
0x 47C
0x 4C8
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image