Heavily Obfuscated JAR Drops Adwind RAT | Sequential Behavior
Try VMRay Analyzer
VTI SCORE: 91/100
Dynamic Analysis Report
Classification: Hacktool, Trojan

fd86a9b0f3bcd1dc2b061bb7a77b3871cb6d101505218f763221ee9945e69bf3 (SHA256)

Bissell New PO.qrypted.jar

Java Archive

Created at 2018-07-19 09:49:00

Notifications (2/2)

Due to a WHOIS service error, no query could be made to get WHOIS data of any contacted domain.

The operating system was rebooted during the analysis.

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xcc0 Analysis Target Medium java.exe "C:\Program Files\Java\jre7\bin\java.exe" -jar "C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar" -
#2 0xd18 Child Process Medium java.exe "C:\Program Files\Java\jre7\bin\java.exe" -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class #1
#3 0xd64 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs #1
#4 0xd78 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs #3
#6 0xdb4 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs #2
#7 0xdc8 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs #6
#10 0xdf8 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs #1
#11 0xe0c Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs #10
#12 0xe1c Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs #2
#13 0xe48 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs #12
#14 0xe58 Child Process Medium xcopy.exe xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e #1
#15 0xe88 Child Process Medium xcopy.exe xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e #2
#16 0xf40 Child Process Medium reg.exe reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v NTMGCGGUKus /t REG_EXPAND_SZ /d "\"C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm\"" /f #1
#17 0xf48 Child Process Medium attrib.exe attrib +h "C:\Users\2XC7u663GxWc\cqsFQOTqbmg\*.*" #1
#18 0xf50 Child Process Medium attrib.exe attrib +h "C:\Users\2XC7u663GxWc\cqsFQOTqbmg" #1
#19 0xf58 Child Process Medium javaw.exe C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe -jar C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm #1
#20 0xfb8 Child Process Medium java.exe C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.080316539076114361006181509658991106.class #19
#21 0x110 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs #19
#22 0x114 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs #21
#23 0x400 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs #20
#24 0x130 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs #23
#25 0x754 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs #19
#26 0x588 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs #20
#27 0x924 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs #26
#28 0x904 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs #25
#30 0x35c Autostart Medium javaw.exe "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm" -
#31 0x290 Child Process Medium java.exe C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class #30
#32 0x558 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs #30
#33 0x7a4 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs #32
#35 0x42c Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs #30
#36 0x174 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs #35
#37 0x7a0 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs #31
#38 0x718 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs #37
#39 0x624 Child Process Medium cmd.exe cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs #31
#40 0x640 Child Process Medium cscript.exe cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs #39

Behavior Information - Sequential View

Process #1: java.exe
7815 5
»
Information Value
ID #1
File Name c:\program files\java\jre7\bin\java.exe
Command Line "C:\Program Files\Java\jre7\bin\java.exe" -jar "C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar"
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:11, Reason: Analysis Target
Unmonitor End Time: 00:00:59, Reason: Self Terminated
Monitor Duration 00:00:48
OS Process Information
»
Information Value
PID 0xcc0
Parent PID 0x3ac (c:\windows\explorer.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x CC4
0x CE0
0x CE8
0x CEC
0x CF0
0x CFC
0x CF4
0x CF8
0x D00
0x D04
0x D08
0x D40
0x D44
0x D48
0x D60
0x EAC
0x F60
0x F74
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory - True - False -
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory - True - False -
pagefile_0x00000000000e0000 0x000e0000 0x000e0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000f0000 0x000f0000 0x000f1fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000100000 0x00100000 0x00106fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory - True - False -
private_0x0000000000120000 0x00120000 0x00120fff Private Memory - True - False -
private_0x0000000000130000 0x00130000 0x00130fff Private Memory - True - False -
3264 0x00140000 0x0014ffff Memory Mapped File - True - False -
private_0x0000000000150000 0x00150000 0x0015ffff Private Memory - True - False -
private_0x0000000000160000 0x00160000 0x0016ffff Private Memory - True - False -
private_0x0000000000170000 0x00170000 0x001bffff Private Memory - True - False -
pagefile_0x00000000001c0000 0x001c0000 0x00287fff Pagefile Backed Memory - True - False -
private_0x0000000000290000 0x00290000 0x002bffff Private Memory - True - False -
private_0x00000000002c0000 0x002c0000 0x002cffff Private Memory - True - False -
rsaenh.dll 0x002d0000 0x0030bfff Memory Mapped File - False - False -
pagefile_0x00000000002d0000 0x002d0000 0x002d0fff Pagefile Backed Memory - True - False -
java.exe 0x00310000 0x0033efff Memory Mapped File - False - False -
pagefile_0x0000000000340000 0x00340000 0x00440fff Pagefile Backed Memory - True - False -
private_0x0000000000450000 0x00450000 0x004cffff Private Memory - True - False -
private_0x00000000004f0000 0x004f0000 0x005effff Private Memory - True - False -
pagefile_0x00000000005f0000 0x005f0000 0x011effff Pagefile Backed Memory - True - False -
private_0x00000000011f0000 0x011f0000 0x012effff Private Memory - True - False -
private_0x0000000001340000 0x01340000 0x0134ffff Private Memory - True - False -
pagefile_0x0000000001350000 0x01350000 0x01742fff Pagefile Backed Memory - True - False -
private_0x0000000001750000 0x01750000 0x0184ffff Private Memory - True - False -
private_0x0000000001850000 0x01850000 0x018affff Private Memory - True - False -
private_0x00000000018b0000 0x018b0000 0x018fffff Private Memory - True - False -
private_0x0000000001910000 0x01910000 0x0191ffff Private Memory - True - False -
private_0x0000000001920000 0x01920000 0x0391ffff Private Memory - True - False -
private_0x0000000003920000 0x03920000 0x039cffff Private Memory - True - False -
private_0x00000000039d0000 0x039d0000 0x03a1ffff Private Memory - True - False -
private_0x0000000003a30000 0x03a30000 0x03a7ffff Private Memory - True - False -
private_0x0000000003ab0000 0x03ab0000 0x03afffff Private Memory - True - False -
private_0x0000000003b00000 0x03b00000 0x03b4ffff Private Memory - True - False -
private_0x0000000003b90000 0x03b90000 0x03bdffff Private Memory - True - False -
private_0x0000000003be0000 0x03be0000 0x03d92fff Private Memory - True - False -
private_0x0000000003c20000 0x03c20000 0x03c6ffff Private Memory - True - False -
private_0x0000000003c70000 0x03c70000 0x03d4ffff Private Memory - True - False -
private_0x0000000003c90000 0x03c90000 0x03cdffff Private Memory - True - False -
private_0x0000000003d10000 0x03d10000 0x03d4ffff Private Memory - True - False -
private_0x0000000003d70000 0x03d70000 0x03dbffff Private Memory - True - False -
private_0x0000000003dc0000 0x03dc0000 0x03e0ffff Private Memory - True - False -
private_0x0000000003e60000 0x03e60000 0x03eaffff Private Memory - True - False -
private_0x0000000003eb0000 0x03eb0000 0x040affff Private Memory - True - False -
sortdefault.nls 0x040b0000 0x0437efff Memory Mapped File - False - False -
private_0x0000000004380000 0x04380000 0x044fffff Private Memory - True - False -
private_0x0000000004380000 0x04380000 0x0449ffff Private Memory - True - False -
private_0x0000000004380000 0x04380000 0x0447ffff Private Memory - True - False -
kernelbase.dll.mui 0x04380000 0x0443ffff Memory Mapped File - False - False -
private_0x0000000004440000 0x04440000 0x0447ffff Private Memory - True - False -
private_0x0000000004490000 0x04490000 0x0449ffff Private Memory - True - False -
private_0x00000000044f0000 0x044f0000 0x044fffff Private Memory - True - False -
private_0x0000000004500000 0x04500000 0x0464ffff Private Memory - True - False -
private_0x0000000004500000 0x04500000 0x045fffff Private Memory - True - False -
private_0x0000000004610000 0x04610000 0x0464ffff Private Memory - True - False -
private_0x0000000004650000 0x04650000 0x04a4ffff Private Memory - True - False -
private_0x0000000004a50000 0x04a50000 0x0524ffff Private Memory - True - False -
private_0x00000000052a0000 0x052a0000 0x052effff Private Memory - True - False -
rpcss.dll 0x052f0000 0x0534bfff Memory Mapped File - False - False -
private_0x00000000053b0000 0x053b0000 0x053fffff Private Memory - True - False -
private_0x0000000005400000 0x05400000 0x055fffff Private Memory - True - False -
pagefile_0x0000000005400000 0x05400000 0x054defff Pagefile Backed Memory - True - False -
private_0x00000000055c0000 0x055c0000 0x055fffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - False - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - False - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - False - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
jvm.dll 0x6b030000 0x6b3affff Memory Mapped File - False - False -
awt.dll 0x6d120000 0x6d262fff Memory Mapped File - True - False -
winmm.dll 0x70250000 0x70281fff Memory Mapped File - False - False -
pnrpnsp.dll 0x71760000 0x71771fff Memory Mapped File - False - False -
winrnr.dll 0x71780000 0x71787fff Memory Mapped File - False - False -
napinsp.dll 0x717a0000 0x717affff Memory Mapped File - False - False -
rasadhlp.dll 0x717b0000 0x717b5fff Memory Mapped File - False - False -
nio.dll 0x71fe0000 0x71feefff Memory Mapped File - True - False -
msvcr100.dll 0x71ff0000 0x720aefff Memory Mapped File - False - False -
net.dll 0x72110000 0x72123fff Memory Mapped File - True - False -
sunec.dll 0x72130000 0x7214ffff Memory Mapped File - False - False -
zip.dll 0x72150000 0x72162fff Memory Mapped File - True - False -
java.dll 0x72170000 0x7218ffff Memory Mapped File - True - False -
verify.dll 0x72190000 0x7219bfff Memory Mapped File - True - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
fwpuclnt.dll 0x737d0000 0x73807fff Memory Mapped File - False - False -
winnsi.dll 0x738e0000 0x738e6fff Memory Mapped File - False - False -
iphlpapi.dll 0x738f0000 0x7390bfff Memory Mapped File - False - False -
nlaapi.dll 0x73a60000 0x73a6ffff Memory Mapped File - False - False -
comctl32.dll 0x73ee0000 0x7407dfff Memory Mapped File - False - False -
wsock32.dll 0x740b0000 0x740b6fff Memory Mapped File - False - False -
wshtcpip.dll 0x744e0000 0x744e4fff Memory Mapped File - False - False -
userenv.dll 0x745b0000 0x745c6fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
dnsapi.dll 0x74850000 0x74893fff Memory Mapped File - False - False -
wship6.dll 0x74980000 0x74985fff Memory Mapped File - False - False -
mswsock.dll 0x74990000 0x749cbfff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
profapi.dll 0x74f00000 0x74f0afff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
psapi.dll 0x76350000 0x76354fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory - True - False -
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 10 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class 241.30 KB MD5: 781fb531354d6f291f1ccab48da6d39f
SHA1: 9ce4518ebcb5be6d1f0b5477fa00c26860fe9a68
SHA256: 97d585b6aff62fb4e43e7e6a5f816dcd7a14be11a88b109a9ba9e8cd4c456eb9
SSDeep: 6144:WI5pxUZ7Gvi8ulm+yV/rIF0/MO2qnan1J7pXESN6U:J5pxAGqNkrIq/MO2qnA
False
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs 0.27 KB MD5: 3bdfd33017806b85949b6faa7d4b98e4
SHA1: f92844fee69ef98db6e68931adfaa9a0a0f8ce66
SHA256: 9da575dd2d5b7c1e9bab8b51a16cde457b3371c6dcdb0537356cf1497fa868f6
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTrLavbx3laDH6djsyn:vmtqvAndZFcrG9lpjsyn
False
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar 621.19 KB MD5: df6fc309f66b3cdb33a8fd183343a610
SHA1: be9e3ae27e19694034f0f7ae81b162befd61689c
SHA256: fd86a9b0f3bcd1dc2b061bb7a77b3871cb6d101505218f763221ee9945e69bf3
SSDeep: 12288:uaVkKWNQXHKobX++/y8rzRZ+otjI+qc+gMNYCEgYjsGGjOXbwlQoMxEVuXLN:5zFfX+Irr+ISc+gh/gY5wla/LN
False
C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt 0.05 KB MD5: 9b201b1dd02cb80825eeb818b96627f3
SHA1: 2bd36111bde69244396c5fb8539c89b714b2e6a5
SHA256: d56585c6039877175e2ebe7a32e04e7c98e947f55839e8cf0e3abc6d06ebb790
SSDeep: 3:YwwAHMaHM3+bIx74Re:YwwAHfHIxsRe
False
Threads
Thread 0xce0
3930 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\program files\java\jre7\bin\client\jvm.dll, base_address = 0x6b030000 True 1
Fn
Module Get Address module_name = c:\program files\java\jre7\bin\client\jvm.dll, function = JVM_GetVersionInfo, address_out = 0x6b11d980 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x7557be77 True 1
Fn
System Get Info type = Hardware Information True 2
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
Module Get Handle module_name = c:\program files\java\jre7\bin\client\jvm.dll, base_address = 0x6b030000 True 1
Fn
Module Get Filename module_name = c:\program files\java\jre7\bin\client\jvm.dll, process_name = c:\program files\java\jre7\bin\java.exe, file_name_orig = C:\Program Files\Java\jre7\bin\client\jvm.dll, size = 260 True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\rt.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1781193, size_out = 1781193 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 709, size_out = 709 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 277, size_out = 277 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2305, size_out = 2305 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1022, size_out = 1022 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2882, size_out = 2882 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 104, size_out = 104 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 728, size_out = 728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 345, size_out = 345 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetFinalPathNameByHandleW, address_out = 0x75574e2a True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 815, size_out = 815 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\bin\zip.dll, type = file_attributes True 3
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1105, size_out = 1105 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1761, size_out = 1761 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 514, size_out = 514 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 970, size_out = 970 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2589, size_out = 2589 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1008, size_out = 1008 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2004, size_out = 2004 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext, type = file_attributes True 2
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 669, size_out = 669 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\meta-index, size = 8192, size_out = 829 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = size, size_out = 829 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 962, size_out = 962 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 934, size_out = 934 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1720, size_out = 1720 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1012, size_out = 1012 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3028, size_out = 3028 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2976, size_out = 2976 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 672, size_out = 672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1189, size_out = 1189 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2646, size_out = 2646 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\access-bridge.jar, type = file_attributes True 3
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 966, size_out = 966 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 800, size_out = 800 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1280, size_out = 1280 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 609, size_out = 609 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 628, size_out = 628 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 327, size_out = 327 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, type = file_attributes True 3
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\management\usagetracker.properties, type = file_attributes False 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 12212, size_out = 12212 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 748, size_out = 748 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6630, size_out = 6630 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3392, size_out = 3392 True 1
Fn
Data
File Create filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 30105, size_out = 30105 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 476, size_out = 476 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2703, size_out = 2703 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 753, size_out = 753 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3690, size_out = 3690 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3361, size_out = 3361 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3599, size_out = 3599 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 260, size_out = 260 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1899, size_out = 1899 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 678, size_out = 678 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\Desktop\Bissell New PO.qrypted.jar, size = 100, size_out = 100 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1909, size_out = 1909 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 670, size_out = 670 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 762, size_out = 762 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1016, size_out = 1016 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1133, size_out = 1133 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 921, size_out = 921 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1133, size_out = 1133 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30105, size_out = 30105 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 100, size_out = 100 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 100, size_out = 100 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 391, size_out = 391 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 452, size_out = 452 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 536, size_out = 536 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 521, size_out = 521 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 491, size_out = 491 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 506, size_out = 506 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 515, size_out = 515 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 361, size_out = 361 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 675, size_out = 675 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 451, size_out = 451 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 355, size_out = 355 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 299, size_out = 299 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 474, size_out = 474 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 655, size_out = 655 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 303, size_out = 303 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 335, size_out = 335 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 418, size_out = 418 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 430, size_out = 430 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 453, size_out = 453 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 555, size_out = 555 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 408, size_out = 408 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 477, size_out = 477 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 562, size_out = 562 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 394, size_out = 394 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 477, size_out = 477 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 462, size_out = 462 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 371, size_out = 371 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 231, size_out = 231 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 691, size_out = 691 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 509, size_out = 509 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 580, size_out = 580 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 391, size_out = 391 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 348, size_out = 348 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 802, size_out = 802 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1127, size_out = 1127 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib, type = file_attributes True 2
Fn
File Read filename = C:\Program Files\Java\jre7\lib\meta-index, size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = size, size_out = 2190 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 3
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 2
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 329, size_out = 329 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 383, size_out = 383 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 332, size_out = 332 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 348, size_out = 348 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 461, size_out = 461 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 570, size_out = 570 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 5504, size_out = 5504 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 582, size_out = 582 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 535, size_out = 535 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 678, size_out = 678 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 315, size_out = 315 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\jce.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 6708, size_out = 6708 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1693, size_out = 1693 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1351, size_out = 1351 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\java.security, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 8192 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 1440 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = size, size_out = 17824 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2345, size_out = 2345 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\jsse.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 13694, size_out = 13694 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1056, size_out = 1056 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3940, size_out = 3940 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5672, size_out = 5672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 844, size_out = 844 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1453, size_out = 1453 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 803, size_out = 803 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2601, size_out = 2601 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1240, size_out = 1240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2666, size_out = 2666 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 314, size_out = 314 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 951, size_out = 951 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 10594, size_out = 10594 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3882, size_out = 3882 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3549, size_out = 3549 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1381, size_out = 1381 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8211, size_out = 8211 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1075, size_out = 1075 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3695, size_out = 3695 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2117, size_out = 2117 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 346, size_out = 346 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 576, size_out = 576 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 24203, size_out = 24203 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 13092, size_out = 13092 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 623, size_out = 623 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3174, size_out = 3174 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2257, size_out = 2257 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1621, size_out = 1621 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2395, size_out = 2395 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 14258, size_out = 14258 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 853, size_out = 853 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 967, size_out = 967 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3914, size_out = 3914 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5828, size_out = 5828 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 12814, size_out = 12814 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4077, size_out = 4077 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2399, size_out = 2399 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2181, size_out = 2181 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 308, size_out = 308 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 381, size_out = 381 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4556, size_out = 4556 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6732, size_out = 6732 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 732, size_out = 732 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 457, size_out = 457 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 973, size_out = 973 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 310, size_out = 310 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2812, size_out = 2812 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 131, size_out = 131 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3431, size_out = 3431 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 281, size_out = 281 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5929, size_out = 5929 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6713, size_out = 6713 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 265, size_out = 265 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6705, size_out = 6705 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3395, size_out = 3395 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1337, size_out = 1337 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5120, size_out = 5120 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 374, size_out = 374 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1663, size_out = 1663 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4945, size_out = 4945 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2801, size_out = 2801 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2263, size_out = 2263 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4843, size_out = 4843 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2266, size_out = 2266 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3589, size_out = 3589 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2498, size_out = 2498 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2363, size_out = 2363 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 631, size_out = 631 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 866, size_out = 866 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 282, size_out = 282 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3850, size_out = 3850 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 591, size_out = 591 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 907, size_out = 907 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3908, size_out = 3908 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8490, size_out = 8490 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 444, size_out = 444 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4645, size_out = 4645 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 11624, size_out = 11624 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 915, size_out = 915 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 687, size_out = 687 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 11725, size_out = 11725 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1715, size_out = 1715 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1952, size_out = 1952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1957, size_out = 1957 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1960, size_out = 1960 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1966, size_out = 1966 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 441, size_out = 441 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 723, size_out = 723 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3045, size_out = 3045 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2242, size_out = 2242 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 387, size_out = 387 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6064, size_out = 6064 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1369, size_out = 1369 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4032, size_out = 4032 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6002, size_out = 6002 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6001, size_out = 6001 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2439, size_out = 2439 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 144, size_out = 144 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1559, size_out = 1559 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 499, size_out = 499 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 734, size_out = 734 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 390, size_out = 390 True 1
Fn
Data
File Get Info filename = C:\Program%20Files\Java\jre7\lib\ext\x86\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Program%20Files\Java\jre7\lib\ext\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\bin\sunec.dll, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 5439, size_out = 5439 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 619, size_out = 619 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 10470, size_out = 10470 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 735, size_out = 735 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4170, size_out = 4170 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 817, size_out = 817 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2357, size_out = 2357 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 187, size_out = 187 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3665, size_out = 3665 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3856, size_out = 3856 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 333, size_out = 333 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\rt.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = time True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\jce.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = time True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 2915, size_out = 2915 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 350, size_out = 350 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 3
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 213, size_out = 213 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 151, size_out = 151 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 92, size_out = 92 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 47, size_out = 47 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 115, size_out = 115 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 502, size_out = 502 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 807, size_out = 807 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 530, size_out = 530 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1987, size_out = 1987 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 706, size_out = 706 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3777, size_out = 3777 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3082, size_out = 3082 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4270, size_out = 4270 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8559, size_out = 8559 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6031, size_out = 6031 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\bin\net.dll, type = file_attributes True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 671, size_out = 671 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1961, size_out = 1961 True 1
Fn
Data
DNS Get Hostname name_out = ZgW5tdPu True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3287, size_out = 3287 True 1
Fn
Data
DNS Resolve Name host = ZgW5tdPu, address_out = fe80:0000:0000:0000:5969:84a4:f9e2:1f2b, 192.168.0.60 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 383, size_out = 383 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3661, size_out = 3661 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 292, size_out = 292 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 389, size_out = 389 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 411, size_out = 411 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 194, size_out = 194 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 1318, size_out = 1318 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 153, size_out = 153 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 209, size_out = 209 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 883, size_out = 883 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 994, size_out = 994 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 780, size_out = 780 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 206, size_out = 206 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 533, size_out = 533 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 775, size_out = 775 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 301, size_out = 301 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 8192, size_out = 8192 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
For performance reasons, the remaining 2740 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xd48
35 0
»
Category Operation Information Success Count Logfile
Module Load module_name = COMCTL32.dll, base_address = 0x73ee0000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x73f009ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x76b4f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x76b4ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x76b5544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x754f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x754f6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x76b55421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x76b4ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x76b5507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x76b4e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6d1b1da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x7637efd7 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 569, size_out = 569 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 333, size_out = 333 True 1
Fn
Data
Module Get Address module_name = c:\windows\system32\user32.dll, function = WaitMessage, address_out = 0x76b566bd True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x76b5634a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address_out = 0x76b4b712 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostMessageW, address_out = 0x76b5447b True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address_out = 0x76b4abe1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address_out = 0x76b4b308 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address_out = 0x7637eba1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetMessageW, address_out = 0x76b5cde8 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = IsWindow, address_out = 0x76b553ba True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address_out = 0x76b4b2f4 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = UnregisterClassW, address_out = 0x76b4b9ae True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = UnhookWindowsHookEx, address_out = 0x76b4adf9 True 1
Fn
Thread 0xd60
3849 0
»
Category Operation Information Success Count Logfile
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 706, size_out = 706 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\Desktop\Bissell New PO.qrypted.jar, size = 3, size_out = 3 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 448, size_out = 448 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4013, size_out = 4013 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1566, size_out = 1566 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 402, size_out = 402 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1366, size_out = 1366 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 9311, size_out = 9311 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3572, size_out = 3572 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1619, size_out = 1619 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2404, size_out = 2404 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3013, size_out = 3013 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1708, size_out = 1708 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2879, size_out = 2879 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1285, size_out = 1285 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1398, size_out = 1398 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1090, size_out = 1090 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3789, size_out = 3789 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 436, size_out = 436 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 792, size_out = 792 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 384, size_out = 384 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1217, size_out = 1217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 480, size_out = 480 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 622, size_out = 622 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 76, size_out = 76 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 527, size_out = 527 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 4051, size_out = 4051 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 7991, size_out = 7991 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 704, size_out = 704 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8401, size_out = 8401 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2096, size_out = 2096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2691, size_out = 2691 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, size = 276 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, os_pid = 0xd64, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 281 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, os_pid = 0xdf8, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, size = 8192, size_out = 108 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes False 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e, os_pid = 0xe58, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 38 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 36 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 39 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 36 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 63 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 56 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 51 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 127 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 49 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 49 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 56 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 51 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 57 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 59 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 57 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 57 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 58 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 42 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 41 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 51 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 53 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 39 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 49 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 43 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 44 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 51 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 59 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 65 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 65 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 65 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 65 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 52 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 66 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 54 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 48 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 51 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 47 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 56 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 50 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 46 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 63 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 65 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 61 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 62 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 61 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 60 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 63 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 66 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 45 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 66 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 64 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 71 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 8192, size_out = 73 True 1
Fn
Data
For performance reasons, the remaining 2845 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xf60
1 0
»
Category Operation Information Success Count Logfile
Module Get Address module_name = c:\windows\system32\user32.dll, function = SendMessageW, address_out = 0x76b55539 True 1
Fn
Process #2: java.exe
2884 5
»
Information Value
ID #2
File Name c:\program files\java\jre7\bin\java.exe
Command Line "C:\Program Files\Java\jre7\bin\java.exe" -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:23, Reason: Child Process
Unmonitor End Time: 00:01:21, Reason: Self Terminated
Monitor Duration 00:00:58
OS Process Information
»
Information Value
PID 0xd18
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x D1C
0x D30
0x D34
0x D38
0x D3C
0x D54
0x D4C
0x D50
0x D5C
0x D58
0x D80
0x D94
0x D98
0x D9C
0x DAC
0x EA8
0x 4CC
0x 93C
0x 980
0x 97C
0x 718
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory - True - False -
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory - True - False -
pagefile_0x00000000000e0000 0x000e0000 0x000e0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000f0000 0x000f0000 0x000f1fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000100000 0x00100000 0x00106fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory - True - False -
private_0x0000000000120000 0x00120000 0x00120fff Private Memory - True - False -
private_0x0000000000130000 0x00130000 0x00130fff Private Memory - True - False -
private_0x0000000000140000 0x00140000 0x0018ffff Private Memory - True - False -
pagefile_0x0000000000190000 0x00190000 0x00257fff Pagefile Backed Memory - True - False -
3352 0x00260000 0x0026ffff Memory Mapped File - True - False -
private_0x0000000000270000 0x00270000 0x002effff Private Memory - True - False -
private_0x00000000002f0000 0x002f0000 0x002fffff Private Memory - True - False -
private_0x0000000000300000 0x00300000 0x0030ffff Private Memory - True - False -
java.exe 0x00310000 0x0033efff Memory Mapped File - False - False -
pagefile_0x0000000000340000 0x00340000 0x00440fff Pagefile Backed Memory - True - False -
private_0x0000000000450000 0x00450000 0x004affff Private Memory - True - False -
private_0x00000000004b0000 0x004b0000 0x005affff Private Memory - True - False -
pagefile_0x00000000005b0000 0x005b0000 0x011affff Pagefile Backed Memory - True - False -
private_0x00000000011b0000 0x011b0000 0x012affff Private Memory - True - False -
private_0x00000000012b0000 0x012b0000 0x0135ffff Private Memory - True - False -
private_0x0000000001360000 0x01360000 0x0136ffff Private Memory - True - False -
private_0x0000000001370000 0x01370000 0x0137ffff Private Memory - True - False -
pagefile_0x0000000001380000 0x01380000 0x01772fff Pagefile Backed Memory - True - False -
pagefile_0x0000000001780000 0x01780000 0x01780fff Pagefile Backed Memory - True - False -
private_0x0000000001790000 0x01790000 0x017dffff Private Memory - True - False -
private_0x00000000017e0000 0x017e0000 0x018dffff Private Memory - True - False -
private_0x00000000018e0000 0x018e0000 0x0190ffff Private Memory - True - False -
private_0x0000000001910000 0x01910000 0x0195ffff Private Memory - True - False -
private_0x0000000001960000 0x01960000 0x0196ffff Private Memory - True - False -
private_0x0000000001970000 0x01970000 0x0396ffff Private Memory - True - False -
private_0x00000000039a0000 0x039a0000 0x039effff Private Memory - True - False -
private_0x0000000003a00000 0x03a00000 0x03a4ffff Private Memory - True - False -
private_0x0000000003a50000 0x03a50000 0x03a8ffff Private Memory - True - False -
private_0x0000000003a90000 0x03a90000 0x03adffff Private Memory - True - False -
private_0x0000000003b10000 0x03b10000 0x03b5ffff Private Memory - True - False -
private_0x0000000003b90000 0x03b90000 0x03bdffff Private Memory - True - False -
rsaenh.dll 0x03be0000 0x03c1bfff Memory Mapped File - False - False -
private_0x0000000003be0000 0x03be0000 0x03c2ffff Private Memory - True - False -
private_0x0000000003bf0000 0x03bf0000 0x03c3ffff Private Memory - True - False -
private_0x0000000003c40000 0x03c40000 0x03c8ffff Private Memory - True - False -
private_0x0000000003c90000 0x03c90000 0x03e42fff Private Memory - True - False -
private_0x0000000003c90000 0x03c90000 0x03d6ffff Private Memory - True - False -
private_0x0000000003c90000 0x03c90000 0x03d0ffff Private Memory - True - False -
private_0x0000000003d10000 0x03d10000 0x03d5ffff Private Memory - True - False -
private_0x0000000003d60000 0x03d60000 0x03d6ffff Private Memory - True - False -
private_0x0000000003d70000 0x03d70000 0x03e2ffff Private Memory - True - False -
rpcss.dll 0x03d70000 0x03dcbfff Memory Mapped File - False - False -
private_0x0000000003d70000 0x03d70000 0x03dbffff Private Memory - True - False -
private_0x0000000003df0000 0x03df0000 0x03e2ffff Private Memory - True - False -
private_0x0000000003e30000 0x03e30000 0x03e7ffff Private Memory - True - False -
private_0x0000000003e80000 0x03e80000 0x0407ffff Private Memory - True - False -
sortdefault.nls 0x04080000 0x0434efff Memory Mapped File - False - False -
private_0x0000000004350000 0x04350000 0x0442ffff Private Memory - True - False -
kernelbase.dll.mui 0x04350000 0x0440ffff Memory Mapped File - False - False -
private_0x0000000004420000 0x04420000 0x0442ffff Private Memory - True - False -
private_0x0000000004430000 0x04430000 0x0452ffff Private Memory - True - False -
private_0x0000000004590000 0x04590000 0x045dffff Private Memory - True - False -
private_0x00000000045f0000 0x045f0000 0x0463ffff Private Memory - True - False -
private_0x0000000004680000 0x04680000 0x046cffff Private Memory - True - False -
private_0x00000000046d0000 0x046d0000 0x0485ffff Private Memory - True - False -
pagefile_0x00000000046d0000 0x046d0000 0x047aefff Pagefile Backed Memory - True - False -
private_0x0000000004820000 0x04820000 0x0485ffff Private Memory - True - False -
private_0x00000000048b0000 0x048b0000 0x048fffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - False - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - False - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - False - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
jvm.dll 0x6b030000 0x6b3affff Memory Mapped File - False - False -
awt.dll 0x6d120000 0x6d262fff Memory Mapped File - True - False -
winmm.dll 0x70250000 0x70281fff Memory Mapped File - False - False -
pnrpnsp.dll 0x71760000 0x71771fff Memory Mapped File - False - False -
winrnr.dll 0x71780000 0x71787fff Memory Mapped File - False - False -
napinsp.dll 0x717a0000 0x717affff Memory Mapped File - False - False -
rasadhlp.dll 0x717b0000 0x717b5fff Memory Mapped File - False - False -
nio.dll 0x71fe0000 0x71feefff Memory Mapped File - True - False -
msvcr100.dll 0x71ff0000 0x720aefff Memory Mapped File - False - False -
net.dll 0x72110000 0x72123fff Memory Mapped File - True - False -
sunec.dll 0x72130000 0x7214ffff Memory Mapped File - False - False -
zip.dll 0x72150000 0x72162fff Memory Mapped File - True - False -
java.dll 0x72170000 0x7218ffff Memory Mapped File - True - False -
verify.dll 0x72190000 0x7219bfff Memory Mapped File - True - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
fwpuclnt.dll 0x737d0000 0x73807fff Memory Mapped File - False - False -
winnsi.dll 0x738e0000 0x738e6fff Memory Mapped File - False - False -
iphlpapi.dll 0x738f0000 0x7390bfff Memory Mapped File - False - False -
nlaapi.dll 0x73a60000 0x73a6ffff Memory Mapped File - False - False -
comctl32.dll 0x73ee0000 0x7407dfff Memory Mapped File - False - False -
wsock32.dll 0x740b0000 0x740b6fff Memory Mapped File - False - False -
wshtcpip.dll 0x744e0000 0x744e4fff Memory Mapped File - False - False -
userenv.dll 0x745b0000 0x745c6fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
dnsapi.dll 0x74850000 0x74893fff Memory Mapped File - False - False -
wship6.dll 0x74980000 0x74985fff Memory Mapped File - False - False -
mswsock.dll 0x74990000 0x749cbfff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
profapi.dll 0x74f00000 0x74f0afff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
psapi.dll 0x76350000 0x76354fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory - True - False -
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 20 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs 0.27 KB MD5: 3bdfd33017806b85949b6faa7d4b98e4
SHA1: f92844fee69ef98db6e68931adfaa9a0a0f8ce66
SHA256: 9da575dd2d5b7c1e9bab8b51a16cde457b3371c6dcdb0537356cf1497fa868f6
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTrLavbx3laDH6djsyn:vmtqvAndZFcrG9lpjsyn
False
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
Threads
Thread 0xd30
2610 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\program files\java\jre7\bin\client\jvm.dll, base_address = 0x6b030000 True 1
Fn
Module Get Address module_name = c:\program files\java\jre7\bin\client\jvm.dll, function = JVM_GetVersionInfo, address_out = 0x6b11d980 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x7557be77 True 1
Fn
System Get Info type = Hardware Information True 2
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
Module Get Handle module_name = c:\program files\java\jre7\bin\client\jvm.dll, base_address = 0x6b030000 True 1
Fn
Module Get Filename module_name = c:\program files\java\jre7\bin\client\jvm.dll, process_name = c:\program files\java\jre7\bin\java.exe, file_name_orig = C:\Program Files\Java\jre7\bin\client\jvm.dll, size = 260 True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\rt.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1781193, size_out = 1781193 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 709, size_out = 709 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 277, size_out = 277 True 1
Fn
Data
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2305, size_out = 2305 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1022, size_out = 1022 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2882, size_out = 2882 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 104, size_out = 104 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 728, size_out = 728 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 345, size_out = 345 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000, flags = GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT, GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetFinalPathNameByHandleW, address_out = 0x75574e2a True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 815, size_out = 815 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\bin\zip.dll, type = file_attributes True 3
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1105, size_out = 1105 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1761, size_out = 1761 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 514, size_out = 514 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 970, size_out = 970 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2589, size_out = 2589 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1008, size_out = 1008 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2004, size_out = 2004 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext, type = file_attributes True 2
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 669, size_out = 669 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\meta-index, size = 8192, size_out = 829 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\meta-index, type = size, size_out = 829 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 962, size_out = 962 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 934, size_out = 934 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1720, size_out = 1720 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1012, size_out = 1012 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3028, size_out = 3028 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2976, size_out = 2976 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 672, size_out = 672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1189, size_out = 1189 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2646, size_out = 2646 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\access-bridge.jar, type = file_attributes True 3
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 966, size_out = 966 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 800, size_out = 800 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1280, size_out = 1280 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 609, size_out = 609 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 628, size_out = 628 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 327, size_out = 327 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = file_attributes True 3
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\management\usagetracker.properties, type = file_attributes False 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 12212, size_out = 12212 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 748, size_out = 748 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6630, size_out = 6630 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3392, size_out = 3392 True 1
Fn
Data
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = time True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 6113, size_out = 6113 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 476, size_out = 476 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2703, size_out = 2703 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 753, size_out = 753 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3690, size_out = 3690 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3361, size_out = 3361 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3599, size_out = 3599 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 260, size_out = 260 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1899, size_out = 1899 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 678, size_out = 678 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 161, size_out = 161 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1909, size_out = 1909 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 670, size_out = 670 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 762, size_out = 762 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1016, size_out = 1016 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1133, size_out = 1133 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 921, size_out = 921 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1133, size_out = 1133 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 6113, size_out = 6113 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 161, size_out = 161 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 161, size_out = 161 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 263, size_out = 263 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 729, size_out = 729 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 243, size_out = 243 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 315, size_out = 315 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 437, size_out = 437 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 439, size_out = 439 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 342, size_out = 342 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 802, size_out = 802 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1127, size_out = 1127 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib, type = file_attributes True 2
Fn
File Read filename = C:\Program Files\Java\jre7\lib\meta-index, size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\meta-index, type = size, size_out = 2190 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 3
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 2
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\classes, type = file_attributes False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 1468, size_out = 1468 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1486, size_out = 1486 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 258, size_out = 258 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2351, size_out = 2351 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 877, size_out = 877 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 645, size_out = 645 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6444, size_out = 6444 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1453, size_out = 1453 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 513, size_out = 513 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4556, size_out = 4556 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\java.security, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 8192 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 1440 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = file_type True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\java.security, type = size, size_out = 17824 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\java.security, size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2345, size_out = 2345 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\jsse.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 13694, size_out = 13694 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1056, size_out = 1056 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3940, size_out = 3940 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5672, size_out = 5672 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 844, size_out = 844 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 803, size_out = 803 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2601, size_out = 2601 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6732, size_out = 6732 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 732, size_out = 732 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 457, size_out = 457 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 973, size_out = 973 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 308, size_out = 308 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 381, size_out = 381 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 310, size_out = 310 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3431, size_out = 3431 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 281, size_out = 281 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 131, size_out = 131 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5929, size_out = 5929 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 405, size_out = 405 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 182, size_out = 182 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 258, size_out = 258 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 3, size_out = 3 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 354, size_out = 354 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 3, size_out = 3 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 645, size_out = 645 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 380, size_out = 380 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 512, size_out = 512 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\jce.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 6708, size_out = 6708 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1693, size_out = 1693 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1351, size_out = 1351 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1240, size_out = 1240 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2666, size_out = 2666 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 314, size_out = 314 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 951, size_out = 951 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 10594, size_out = 10594 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3882, size_out = 3882 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3549, size_out = 3549 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1381, size_out = 1381 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8211, size_out = 8211 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1075, size_out = 1075 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3695, size_out = 3695 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2117, size_out = 2117 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 346, size_out = 346 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 576, size_out = 576 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 24203, size_out = 24203 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 13092, size_out = 13092 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 623, size_out = 623 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3174, size_out = 3174 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2257, size_out = 2257 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1621, size_out = 1621 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2395, size_out = 2395 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 14258, size_out = 14258 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 853, size_out = 853 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 967, size_out = 967 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3914, size_out = 3914 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5828, size_out = 5828 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 12814, size_out = 12814 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4077, size_out = 4077 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2399, size_out = 2399 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2181, size_out = 2181 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2812, size_out = 2812 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6713, size_out = 6713 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 265, size_out = 265 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6705, size_out = 6705 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3395, size_out = 3395 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1337, size_out = 1337 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5120, size_out = 5120 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 374, size_out = 374 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1663, size_out = 1663 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4945, size_out = 4945 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2801, size_out = 2801 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2263, size_out = 2263 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4843, size_out = 4843 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2266, size_out = 2266 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3589, size_out = 3589 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2498, size_out = 2498 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2363, size_out = 2363 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 631, size_out = 631 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 866, size_out = 866 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 282, size_out = 282 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3850, size_out = 3850 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 591, size_out = 591 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 907, size_out = 907 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3908, size_out = 3908 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8490, size_out = 8490 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 444, size_out = 444 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4645, size_out = 4645 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 11624, size_out = 11624 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 915, size_out = 915 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 687, size_out = 687 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 11725, size_out = 11725 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1715, size_out = 1715 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1952, size_out = 1952 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1957, size_out = 1957 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1960, size_out = 1960 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1966, size_out = 1966 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 441, size_out = 441 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 723, size_out = 723 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3045, size_out = 3045 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2242, size_out = 2242 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 387, size_out = 387 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6064, size_out = 6064 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1369, size_out = 1369 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4032, size_out = 4032 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6002, size_out = 6002 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6001, size_out = 6001 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2439, size_out = 2439 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 144, size_out = 144 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1559, size_out = 1559 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 499, size_out = 499 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 734, size_out = 734 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 390, size_out = 390 True 1
Fn
Data
File Get Info filename = C:\Program%20Files\Java\jre7\lib\ext\x86\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Program%20Files\Java\jre7\lib\ext\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\bin\sunec.dll, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 5439, size_out = 5439 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 619, size_out = 619 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 10470, size_out = 10470 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 735, size_out = 735 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4170, size_out = 4170 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 817, size_out = 817 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2357, size_out = 2357 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 187, size_out = 187 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3665, size_out = 3665 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3856, size_out = 3856 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 333, size_out = 333 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\rt.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\rt.jar, type = time True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = file_attributes True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\jce.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\jce.jar, type = time True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 2915, size_out = 2915 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 350, size_out = 350 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 3
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 213, size_out = 213 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 151, size_out = 151 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 92, size_out = 92 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 47, size_out = 47 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\US_export_policy.jar, size = 115, size_out = 115 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 502, size_out = 502 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 807, size_out = 807 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 530, size_out = 530 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 1987, size_out = 1987 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 706, size_out = 706 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 4096, size_out = 4096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3777, size_out = 3777 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 3082, size_out = 3082 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4270, size_out = 4270 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8559, size_out = 8559 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6031, size_out = 6031 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\bin\net.dll, type = file_attributes True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 671, size_out = 671 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1961, size_out = 1961 True 1
Fn
Data
DNS Get Hostname name_out = ZgW5tdPu True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3287, size_out = 3287 True 1
Fn
Data
DNS Resolve Name host = ZgW5tdPu, address_out = fe80:0000:0000:0000:5969:84a4:f9e2:1f2b, 192.168.0.60 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 383, size_out = 383 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3661, size_out = 3661 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 292, size_out = 292 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, type = time True 1
Fn
File Create filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 389, size_out = 389 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 411, size_out = 411 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 194, size_out = 194 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 1318, size_out = 1318 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 153, size_out = 153 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 209, size_out = 209 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 883, size_out = 883 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 994, size_out = 994 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 780, size_out = 780 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\security\local_policy.jar, size = 206, size_out = 206 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 533, size_out = 533 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 775, size_out = 775 True 1
Fn
Data
File Create filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jce.jar, size = 301, size_out = 301 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 8192, size_out = 8192 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1137, size_out = 1137 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1486, size_out = 1486 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1009, size_out = 1009 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1052, size_out = 1052 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 269, size_out = 269 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1438, size_out = 1438 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 2684, size_out = 2684 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 157, size_out = 157 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 902, size_out = 902 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1516, size_out = 1516 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 925, size_out = 925 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1403, size_out = 1403 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 684, size_out = 684 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 2171, size_out = 2171 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1421, size_out = 1421 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 694, size_out = 694 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 171, size_out = 171 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 814, size_out = 814 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 608, size_out = 608 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 677, size_out = 677 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 274, size_out = 274 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1343, size_out = 1343 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 541, size_out = 541 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 2912, size_out = 2912 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1249, size_out = 1249 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1311, size_out = 1311 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 265, size_out = 265 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 1605, size_out = 1605 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 557, size_out = 557 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 173, size_out = 173 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 2789, size_out = 2789 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
For performance reasons, the remaining 1482 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xd4c
3 0
»
Category Operation Information Success Count Logfile
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 541, size_out = 541 True 1
Fn
Data
Thread 0xd9c
37 0
»
Category Operation Information Success Count Logfile
Module Load module_name = COMCTL32.dll, base_address = 0x73ee0000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x73f009ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x76b4f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x76b4ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x76b5544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x754f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x754f6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x76b55421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x76b4ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x76b5507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x76b4e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6d1b1da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x7637efd7 True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 569, size_out = 569 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 333, size_out = 333 True 1
Fn
Data
Module Get Address module_name = c:\windows\system32\user32.dll, function = WaitMessage, address_out = 0x76b566bd True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x76b5634a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = IsWindow, address_out = 0x76b553ba True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetWindowThreadProcessId, address_out = 0x76b4ee32 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SendMessageW, address_out = 0x76b55539 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address_out = 0x76b4abe1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = TranslateMessage, address_out = 0x76b564c7 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DispatchMessageW, address_out = 0x76b5cc61 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address_out = 0x76b4b712 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostMessageW, address_out = 0x76b5447b True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address_out = 0x76b4b308 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address_out = 0x7637eba1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetMessageW, address_out = 0x76b5cde8 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address_out = 0x76b4b2f4 True 1
Fn
Thread 0xdac
233 0
»
Category Operation Information Success Count Logfile
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.77866636596601243045465905282659207.class, size = 390, size_out = 390 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 448, size_out = 448 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 4013, size_out = 4013 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1566, size_out = 1566 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 402, size_out = 402 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1366, size_out = 1366 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 9311, size_out = 9311 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3572, size_out = 3572 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1619, size_out = 1619 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2404, size_out = 2404 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3013, size_out = 3013 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1708, size_out = 1708 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2879, size_out = 2879 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1285, size_out = 1285 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1398, size_out = 1398 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1090, size_out = 1090 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 3789, size_out = 3789 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 436, size_out = 436 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 792, size_out = 792 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 384, size_out = 384 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 1217, size_out = 1217 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 480, size_out = 480 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 622, size_out = 622 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 76, size_out = 76 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 527, size_out = 527 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 4051, size_out = 4051 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 7991, size_out = 7991 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 704, size_out = 704 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 8401, size_out = 8401 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\jsse.jar, size = 2096, size_out = 2096 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 2691, size_out = 2691 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1664, size_out = 1664 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, size = 276 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 6028, size_out = 6028 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 7832, size_out = 7832 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5512, size_out = 5512 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 949, size_out = 949 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1167, size_out = 1167 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1427, size_out = 1427 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1429, size_out = 1429 True 1
Fn
Data
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, os_pid = 0xdb4, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1873, size_out = 1873 True 1
Fn
Data
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, size = 281 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, os_pid = 0xe1c, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes False 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e, os_pid = 0xe88, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, size = 8192, size_out = 40 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, size = 8192, size_out = 39 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, size = 8192, size_out = 0 False 2
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes True 1
Fn
File Create filename = C:\Windows\System32\test.txt, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1396, size_out = 1396 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 582, size_out = 582 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 46400, size_out = 46400 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 263, size_out = 263 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 357, size_out = 357 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5472, size_out = 5472 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 3241, size_out = 3241 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 784, size_out = 784 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1886, size_out = 1886 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 5529, size_out = 5529 True 1
Fn
Data
File Get Info filename = C:\Program Files\Java\jre7\bin\net.dll, type = file_attributes True 3
Fn
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 1188, size_out = 1188 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Program Files\Java\jre7\lib\rt.jar, size = 213, size_out = 213 True 1
Fn
Data
Module Load module_name = IPHLPAPI.DLL, base_address = 0x738f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIfTable, address_out = 0x738fae94 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetFriendlyIfIndex, address_out = 0x738fd855 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIpAddrTable, address_out = 0x738f9bb0 True 1
Fn
Thread 0x718
1 0
»
Category Operation Information Success Count Logfile
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
Process #3: cmd.exe
58 0
»
Information Value
ID #3
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:29, Reason: Child Process
Unmonitor End Time: 00:00:42, Reason: Self Terminated
Monitor Duration 00:00:13
OS Process Information
»
Information Value
PID 0xd64
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x D68
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory - True - False -
private_0x0000000000060000 0x00060000 0x0015ffff Private Memory - True - False -
pagefile_0x0000000000160000 0x00160000 0x00161fff Pagefile Backed Memory - True - False -
private_0x0000000000170000 0x00170000 0x00170fff Private Memory - True - False -
private_0x0000000000180000 0x00180000 0x00180fff Private Memory - True - False -
cscript.exe 0x00190000 0x001b1fff Memory Mapped File - False - False -
private_0x00000000001c0000 0x001c0000 0x002bffff Private Memory - True - False -
locale.nls 0x002c0000 0x00326fff Memory Mapped File - False - False -
cscript.exe.mui 0x00330000 0x00332fff Memory Mapped File - False - False -
private_0x00000000003f0000 0x003f0000 0x003fffff Private Memory - True - False -
pagefile_0x0000000000400000 0x00400000 0x004c7fff Pagefile Backed Memory - True - False -
pagefile_0x00000000004d0000 0x004d0000 0x005d0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000005e0000 0x005e0000 0x011dffff Pagefile Backed Memory - True - False -
pagefile_0x00000000011e0000 0x011e0000 0x0146afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01470000 0x0173efff Memory Mapped File - False - False -
cmd.exe 0x4a430000 0x4a47bfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xd68
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:34 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10885141 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a430000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7u663GxWc\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0xd78, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #4: cscript.exe
93 0
»
Information Value
ID #4
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:30, Reason: Child Process
Unmonitor End Time: 00:00:42, Reason: Self Terminated
Monitor Duration 00:00:12
OS Process Information
»
Information Value
PID 0xd78
Parent PID 0xd64 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x D7C
0x D84
0x D88
0x D8C
0x D90
0x DA0
0x DA4
0x DA8
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x00177fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000180000 0x00180000 0x00186fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000190000 0x00190000 0x00191fff Pagefile Backed Memory - True - False -
private_0x00000000001a0000 0x001a0000 0x0029ffff Private Memory - True - False -
pagefile_0x00000000002a0000 0x002a0000 0x003a0fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x003b0000 0x003b2fff Memory Mapped File - False - False -
private_0x00000000003c0000 0x003c0000 0x003c0fff Private Memory - True - False -
private_0x00000000003d0000 0x003d0000 0x003d0fff Private Memory - True - False -
rpcss.dll 0x003e0000 0x0043bfff Memory Mapped File - False - False -
cscript.exe 0x003e0000 0x003ebfff Memory Mapped File - True - False -
pagefile_0x00000000003f0000 0x003f0000 0x003f0fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000400000 0x00400000 0x00400fff Pagefile Backed Memory - True - False -
retrive2955724691501239824.vbs 0x00410000 0x00410fff Memory Mapped File - True - False -
rsaenh.dll 0x00410000 0x0044bfff Memory Mapped File - False - False -
private_0x0000000000410000 0x00410000 0x0041ffff Private Memory - True - False -
retrive2955724691501239824.vbs 0x00420000 0x00420fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00420000 0x0042efff Memory Mapped File - False - False -
private_0x0000000000450000 0x00450000 0x0045ffff Private Memory - True - False -
private_0x0000000000460000 0x00460000 0x0055ffff Private Memory - True - False -
private_0x0000000000560000 0x00560000 0x0067ffff Private Memory - True - False -
pagefile_0x0000000000560000 0x00560000 0x0063efff Pagefile Backed Memory - True - False -
private_0x0000000000640000 0x00640000 0x0067ffff Private Memory - True - False -
private_0x0000000000680000 0x00680000 0x0077ffff Private Memory - True - False -
sortdefault.nls 0x00780000 0x00a4efff Memory Mapped File - False - False -
private_0x0000000000a90000 0x00a90000 0x00b8ffff Private Memory - True - False -
private_0x0000000000c00000 0x00c00000 0x00cfffff Private Memory - True - False -
cscript.exe 0x00d10000 0x00d31fff Memory Mapped File - True - False -
pagefile_0x0000000000d40000 0x00d40000 0x0193ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001940000 0x01940000 0x01d3ffff Pagefile Backed Memory - True - False -
private_0x0000000001d80000 0x01d80000 0x01e7ffff Private Memory - True - False -
private_0x0000000001e80000 0x01e80000 0x01f4ffff Private Memory - True - False -
private_0x0000000001f50000 0x01f50000 0x0204ffff Private Memory - True - False -
private_0x0000000002050000 0x02050000 0x0222ffff Private Memory - True - False -
private_0x0000000002050000 0x02050000 0x021bffff Private Memory - True - False -
private_0x00000000021f0000 0x021f0000 0x0222ffff Private Memory - True - False -
private_0x0000000002330000 0x02330000 0x0242ffff Private Memory - True - False -
private_0x0000000002450000 0x02450000 0x0254ffff Private Memory - True - False -
private_0x0000000002550000 0x02550000 0x0264ffff Private Memory - True - False -
comctl32.dll 0x6ced0000 0x6cf53fff Memory Mapped File - False - False -
vbscript.dll 0x6cf60000 0x6cfcafff Memory Mapped File - True - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
wbemdisp.dll 0x71fa0000 0x71fd0fff Memory Mapped File - True - False -
scrobj.dll 0x720b0000 0x720dcfff Memory Mapped File - True - False -
wshext.dll 0x720e0000 0x720f5fff Memory Mapped File - True - False -
msisip.dll 0x72100000 0x72107fff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xd7c
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:35 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10885640 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xd10000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 100, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 100, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 100, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 213, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 213, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 176, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 176, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10886576 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive2955724691501239824.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0xd88
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 4530984 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 4530984 False 1
Fn
Process #6: cmd.exe
58 0
»
Information Value
ID #6
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:40, Reason: Child Process
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0xdb4
Parent PID 0xd18 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x DB8
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x00187fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000190000 0x00190000 0x00196fff Pagefile Backed Memory - True - False -
pagefile_0x00000000001a0000 0x001a0000 0x001a1fff Pagefile Backed Memory - True - False -
private_0x00000000001b0000 0x001b0000 0x001b0fff Private Memory - True - False -
private_0x00000000001c0000 0x001c0000 0x002bffff Private Memory - True - False -
pagefile_0x00000000002c0000 0x002c0000 0x003c0fff Pagefile Backed Memory - True - False -
private_0x00000000003d0000 0x003d0000 0x003d0fff Private Memory - True - False -
cscript.exe 0x003e0000 0x00401fff Memory Mapped File - False - False -
cscript.exe.mui 0x00410000 0x00412fff Memory Mapped File - False - False -
private_0x0000000000420000 0x00420000 0x0042ffff Private Memory - True - False -
private_0x0000000000470000 0x00470000 0x0056ffff Private Memory - True - False -
pagefile_0x0000000000570000 0x00570000 0x0116ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001170000 0x01170000 0x013fafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01400000 0x016cefff Memory Mapped File - False - False -
cmd.exe 0x4a430000 0x4a47bfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xdb8
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:40 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10891178 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a430000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7u663GxWc\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0xdc8, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #7: cscript.exe
93 0
»
Information Value
ID #7
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:40, Reason: Child Process
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0xdc8
Parent PID 0xdb4 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x DCC
0x DD0
0x DD4
0x DD8
0x DDC
0x DE4
0x DEC
0x DF0
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
cscript.exe 0x00100000 0x0010bfff Memory Mapped File - True - False -
private_0x0000000000110000 0x00110000 0x0020ffff Private Memory - True - False -
pagefile_0x0000000000210000 0x00210000 0x002d7fff Pagefile Backed Memory - True - False -
rpcss.dll 0x002e0000 0x0033bfff Memory Mapped File - False - False -
pagefile_0x00000000002e0000 0x002e0000 0x002e0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000002f0000 0x002f0000 0x002f0fff Pagefile Backed Memory - True - False -
retrive3009091646390096651.vbs 0x00300000 0x00300fff Memory Mapped File - True - False -
rsaenh.dll 0x00300000 0x0033bfff Memory Mapped File - False - False -
private_0x0000000000300000 0x00300000 0x0030ffff Private Memory - True - False -
retrive3009091646390096651.vbs 0x00310000 0x00310fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00310000 0x0031efff Memory Mapped File - False - False -
private_0x0000000000340000 0x00340000 0x0034ffff Private Memory - True - False -
private_0x0000000000360000 0x00360000 0x0045ffff Private Memory - True - False -
pagefile_0x0000000000460000 0x00460000 0x00560fff Pagefile Backed Memory - True - False -
private_0x0000000000570000 0x00570000 0x006cffff Private Memory - True - False -
pagefile_0x0000000000570000 0x00570000 0x0064efff Pagefile Backed Memory - True - False -
private_0x0000000000690000 0x00690000 0x006cffff Private Memory - True - False -
private_0x00000000006d0000 0x006d0000 0x0072ffff Private Memory - True - False -
private_0x0000000000800000 0x00800000 0x008fffff Private Memory - True - False -
sortdefault.nls 0x00900000 0x00bcefff Memory Mapped File - False - False -
private_0x0000000000bf0000 0x00bf0000 0x00ceffff Private Memory - True - False -
cscript.exe 0x00d10000 0x00d31fff Memory Mapped File - True - False -
pagefile_0x0000000000d40000 0x00d40000 0x0193ffff Pagefile Backed Memory - True - False -
private_0x0000000001940000 0x01940000 0x01a3ffff Private Memory - True - False -
private_0x0000000001a40000 0x01a40000 0x01b3ffff Private Memory - True - False -
pagefile_0x0000000001b40000 0x01b40000 0x01f3ffff Pagefile Backed Memory - True - False -
private_0x0000000001f80000 0x01f80000 0x0207ffff Private Memory - True - False -
private_0x0000000002080000 0x02080000 0x0217ffff Private Memory - True - False -
private_0x0000000002180000 0x02180000 0x0229ffff Private Memory - True - False -
private_0x0000000002360000 0x02360000 0x0245ffff Private Memory - True - False -
private_0x00000000024a0000 0x024a0000 0x0259ffff Private Memory - True - False -
private_0x00000000025b0000 0x025b0000 0x026affff Private Memory - True - False -
comctl32.dll 0x6ced0000 0x6cf53fff Memory Mapped File - False - False -
vbscript.dll 0x6cf60000 0x6cfcafff Memory Mapped File - True - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
wbemdisp.dll 0x71fa0000 0x71fd0fff Memory Mapped File - True - False -
scrobj.dll 0x720b0000 0x720dcfff Memory Mapped File - True - False -
wshext.dll 0x720e0000 0x720f5fff Memory Mapped File - True - False -
msisip.dll 0x72100000 0x72107fff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xdcc
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:40 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10891272 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xd10000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 54, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 54, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10891490 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3009091646390096651.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0xdd4
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 3416872 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 3416872 False 1
Fn
Process #10: cmd.exe
58 0
»
Information Value
ID #10
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:41, Reason: Child Process
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0xdf8
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x DFC
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
private_0x0000000000050000 0x00050000 0x0005ffff Private Memory - True - False -
pagefile_0x0000000000060000 0x00060000 0x00066fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000070000 0x00070000 0x00071fff Pagefile Backed Memory - True - False -
private_0x0000000000080000 0x00080000 0x00080fff Private Memory - True - False -
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory - True - False -
private_0x0000000000190000 0x00190000 0x00190fff Private Memory - True - False -
cscript.exe 0x001a0000 0x001c1fff Memory Mapped File - False - False -
cscript.exe.mui 0x001d0000 0x001d2fff Memory Mapped File - False - False -
private_0x00000000001e0000 0x001e0000 0x002dffff Private Memory - True - False -
locale.nls 0x002e0000 0x00346fff Memory Mapped File - False - False -
pagefile_0x0000000000350000 0x00350000 0x00417fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000420000 0x00420000 0x00520fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000530000 0x00530000 0x0112ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001130000 0x01130000 0x013bafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x013c0000 0x0168efff Memory Mapped File - False - False -
cmd.exe 0x4a430000 0x4a47bfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xdfc
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:42 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10892645 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a430000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7u663GxWc\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0xe0c, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #11: cscript.exe
92 0
»
Information Value
ID #11
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0xe0c
Parent PID 0xdf8 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x E10
0x E18
0x E2C
0x E34
0x E38
0x E3C
0x E40
0x E44
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
private_0x00000000000c0000 0x000c0000 0x000cffff Private Memory - True - False -
pagefile_0x00000000000d0000 0x000d0000 0x00197fff Pagefile Backed Memory - True - False -
pagefile_0x00000000001a0000 0x001a0000 0x001a1fff Pagefile Backed Memory - True - False -
private_0x00000000001b0000 0x001b0000 0x002affff Private Memory - True - False -
pagefile_0x00000000002b0000 0x002b0000 0x003b0fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x003c0000 0x003c2fff Memory Mapped File - False - False -
private_0x00000000003d0000 0x003d0000 0x004cffff Private Memory - True - False -
private_0x00000000004d0000 0x004d0000 0x004d0fff Private Memory - True - False -
private_0x00000000004e0000 0x004e0000 0x004e0fff Private Memory - True - False -
rpcss.dll 0x004f0000 0x0054bfff Memory Mapped File - False - False -
private_0x00000000004f0000 0x004f0000 0x005fffff Private Memory - True - False -
cscript.exe 0x004f0000 0x004fbfff Memory Mapped File - True - False -
pagefile_0x0000000000500000 0x00500000 0x00500fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000510000 0x00510000 0x00510fff Pagefile Backed Memory - True - False -
retrive4432003530389164433.vbs 0x00520000 0x00520fff Memory Mapped File - True - False -
rsaenh.dll 0x00520000 0x0055bfff Memory Mapped File - False - False -
private_0x0000000000520000 0x00520000 0x0052ffff Private Memory - True - False -
retrive4432003530389164433.vbs 0x00530000 0x00530fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00530000 0x0053efff Memory Mapped File - False - False -
private_0x00000000005c0000 0x005c0000 0x005fffff Private Memory - True - False -
pagefile_0x0000000000600000 0x00600000 0x006defff Pagefile Backed Memory - True - False -
private_0x0000000000730000 0x00730000 0x0082ffff Private Memory - True - False -
private_0x0000000000880000 0x00880000 0x0097ffff Private Memory - True - False -
sortdefault.nls 0x00980000 0x00c4efff Memory Mapped File - False - False -
cscript.exe 0x00d10000 0x00d31fff Memory Mapped File - True - False -
pagefile_0x0000000000d40000 0x00d40000 0x0193ffff Pagefile Backed Memory - True - False -
private_0x00000000019b0000 0x019b0000 0x01aaffff Private Memory - True - False -
pagefile_0x0000000001ab0000 0x01ab0000 0x01eaffff Pagefile Backed Memory - True - False -
private_0x0000000001eb0000 0x01eb0000 0x01ffffff Private Memory - True - False -
private_0x0000000001eb0000 0x01eb0000 0x01faffff Private Memory - True - False -
private_0x0000000001ff0000 0x01ff0000 0x01ffffff Private Memory - True - False -
private_0x0000000002020000 0x02020000 0x0211ffff Private Memory - True - False -
private_0x0000000002120000 0x02120000 0x0221ffff Private Memory - True - False -
private_0x0000000002220000 0x02220000 0x0235ffff Private Memory - True - False -
private_0x00000000023c0000 0x023c0000 0x024bffff Private Memory - True - False -
private_0x00000000024d0000 0x024d0000 0x025cffff Private Memory - True - False -
private_0x0000000002640000 0x02640000 0x0273ffff Private Memory - True - False -
comctl32.dll 0x6ce60000 0x6cee3fff Memory Mapped File - False - False -
vbscript.dll 0x6cef0000 0x6cf5afff Memory Mapped File - True - False -
wbemdisp.dll 0x6cf90000 0x6cfc0fff Memory Mapped File - True - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
scrobj.dll 0x71fb0000 0x71fdcfff Memory Mapped File - True - False -
wshext.dll 0x720d0000 0x720e5fff Memory Mapped File - True - False -
msisip.dll 0x720f0000 0x720f7fff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xe10
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:42 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10892707 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xd10000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 181, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 181, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10892785 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0xe2c
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 795432 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 795432 False 1
Fn
Process #12: cmd.exe
58 0
»
Information Value
ID #12
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:00:44, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0xe1c
Parent PID 0xd18 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x E20
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory - True - False -
private_0x00000000000e0000 0x000e0000 0x000effff Private Memory - True - False -
pagefile_0x00000000000f0000 0x000f0000 0x001b7fff Pagefile Backed Memory - True - False -
private_0x00000000001c0000 0x001c0000 0x001c0fff Private Memory - True - False -
private_0x00000000001d0000 0x001d0000 0x001d0fff Private Memory - True - False -
cscript.exe 0x001e0000 0x00201fff Memory Mapped File - False - False -
cscript.exe.mui 0x00210000 0x00212fff Memory Mapped File - False - False -
private_0x0000000000220000 0x00220000 0x0031ffff Private Memory - True - False -
pagefile_0x0000000000320000 0x00320000 0x00420fff Pagefile Backed Memory - True - False -
private_0x0000000000480000 0x00480000 0x0057ffff Private Memory - True - False -
pagefile_0x0000000000580000 0x00580000 0x0117ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001180000 0x01180000 0x0140afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01410000 0x016defff Memory Mapped File - False - False -
cmd.exe 0x4a430000 0x4a47bfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xe20
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:42 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10892910 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a430000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\Desktop, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7u663GxWc\Desktop True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0xe48, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #13: cscript.exe
92 0
»
Information Value
ID #13
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:00:44, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0xe48
Parent PID 0xe1c (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x E4C
0x E54
0x E60
0x E6C
0x E70
0x E74
0x E7C
0x E80
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
cscript.exe 0x00100000 0x0010bfff Memory Mapped File - True - False -
pagefile_0x0000000000110000 0x00110000 0x00110fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000120000 0x00120000 0x00120fff Pagefile Backed Memory - True - False -
retrive8453022226677560905.vbs 0x00130000 0x00130fff Memory Mapped File - True - False -
private_0x0000000000130000 0x00130000 0x0013ffff Private Memory - True - False -
retrive8453022226677560905.vbs 0x00140000 0x00140fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00140000 0x0014efff Memory Mapped File - False - False -
private_0x0000000000150000 0x00150000 0x0015ffff Private Memory - True - False -
rpcss.dll 0x00160000 0x001bbfff Memory Mapped File - False - False -
rsaenh.dll 0x00160000 0x0019bfff Memory Mapped File - False - False -
private_0x00000000001d0000 0x001d0000 0x002cffff Private Memory - True - False -
pagefile_0x00000000002d0000 0x002d0000 0x00397fff Pagefile Backed Memory - True - False -
private_0x0000000000450000 0x00450000 0x0054ffff Private Memory - True - False -
pagefile_0x0000000000550000 0x00550000 0x00650fff Pagefile Backed Memory - True - False -
private_0x0000000000660000 0x00660000 0x0071ffff Private Memory - True - False -
pagefile_0x0000000000720000 0x00720000 0x007fefff Pagefile Backed Memory - True - False -
private_0x0000000000800000 0x00800000 0x0096ffff Private Memory - True - False -
private_0x0000000000800000 0x00800000 0x008fffff Private Memory - True - False -
private_0x0000000000960000 0x00960000 0x0096ffff Private Memory - True - False -
private_0x0000000000970000 0x00970000 0x00a6ffff Private Memory - True - False -
private_0x0000000000b70000 0x00b70000 0x00c6ffff Private Memory - True - False -
cscript.exe 0x00d10000 0x00d31fff Memory Mapped File - True - False -
pagefile_0x0000000000d40000 0x00d40000 0x0193ffff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01940000 0x01c0efff Memory Mapped File - False - False -
private_0x0000000001cf0000 0x01cf0000 0x01deffff Private Memory - True - False -
pagefile_0x0000000001df0000 0x01df0000 0x021effff Pagefile Backed Memory - True - False -
private_0x00000000021f0000 0x021f0000 0x022effff Private Memory - True - False -
private_0x00000000022f0000 0x022f0000 0x024cffff Private Memory - True - False -
private_0x0000000002390000 0x02390000 0x0248ffff Private Memory - True - False -
private_0x0000000002490000 0x02490000 0x024cffff Private Memory - True - False -
private_0x00000000024d0000 0x024d0000 0x0268ffff Private Memory - True - False -
private_0x0000000002500000 0x02500000 0x025fffff Private Memory - True - False -
private_0x0000000002650000 0x02650000 0x0268ffff Private Memory - True - False -
private_0x00000000026c0000 0x026c0000 0x027bffff Private Memory - True - False -
comctl32.dll 0x6ced0000 0x6cf53fff Memory Mapped File - False - False -
vbscript.dll 0x6cf60000 0x6cfcafff Memory Mapped File - True - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
wbemdisp.dll 0x71fa0000 0x71fd0fff Memory Mapped File - True - False -
scrobj.dll 0x720b0000 0x720dcfff Memory Mapped File - True - False -
wshext.dll 0x720e0000 0x720f5fff Memory Mapped File - True - False -
msisip.dll 0x72100000 0x72107fff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xe4c
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:42 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10893003 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xd10000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 30, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 30, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10893159 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive8453022226677560905.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0xe60
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 1385256 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 1385256 False 1
Fn
Process #14: xcopy.exe
0 0
»
Information Value
ID #14
File Name c:\windows\system32\xcopy.exe
Command Line xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:42, Reason: Child Process
Unmonitor End Time: 00:00:56, Reason: Self Terminated
Monitor Duration 00:00:14
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xe58
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x E5C
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
private_0x0000000000080000 0x00080000 0x0017ffff Private Memory - True - False -
private_0x00000000001c0000 0x001c0000 0x001fffff Private Memory - True - False -
locale.nls 0x00200000 0x00266fff Memory Mapped File - False - False -
pagefile_0x0000000000270000 0x00270000 0x00337fff Pagefile Backed Memory - True - False -
private_0x0000000000390000 0x00390000 0x0039ffff Private Memory - True - False -
xcopy.exe 0x003b0000 0x003bbfff Memory Mapped File - False - False -
ifsutil.dll 0x6d8f0000 0x6d916fff Memory Mapped File - False - False -
ulib.dll 0x71f80000 0x71f9cfff Memory Mapped File - False - False -
devobj.dll 0x750a0000 0x750b1fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
cfgmgr32.dll 0x751d0000 0x751f6fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
setupapi.dll 0x76c10000 0x76dacfff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Process #15: xcopy.exe
0 0
»
Information Value
ID #15
File Name c:\windows\system32\xcopy.exe
Command Line xcopy "C:\Program Files\Java\jre7" "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\" /e
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:43, Reason: Child Process
Unmonitor End Time: 00:01:21, Reason: Self Terminated
Monitor Duration 00:00:38
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xe88
Parent PID 0xd18 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x E8C
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
private_0x0000000000070000 0x00070000 0x000affff Private Memory - True - False -
private_0x0000000000110000 0x00110000 0x0020ffff Private Memory - True - False -
locale.nls 0x00210000 0x00276fff Memory Mapped File - False - False -
pagefile_0x0000000000280000 0x00280000 0x00347fff Pagefile Backed Memory - True - False -
xcopy.exe 0x003b0000 0x003bbfff Memory Mapped File - False - False -
private_0x0000000000580000 0x00580000 0x0058ffff Private Memory - True - False -
ifsutil.dll 0x6d8f0000 0x6d916fff Memory Mapped File - False - False -
ulib.dll 0x71f80000 0x71f9cfff Memory Mapped File - False - False -
devobj.dll 0x750a0000 0x750b1fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
cfgmgr32.dll 0x751d0000 0x751f6fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
setupapi.dll 0x76c10000 0x76dacfff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Process #16: reg.exe
10 0
»
Information Value
ID #16
File Name c:\windows\system32\reg.exe
Command Line reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v NTMGCGGUKus /t REG_EXPAND_SZ /d "\"C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe\" -jar \"C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm\"" /f
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:00:59, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0xf40
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x F44
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory - True - False -
private_0x0000000000060000 0x00060000 0x0009ffff Private Memory - True - False -
locale.nls 0x000a0000 0x00106fff Memory Mapped File - False - False -
pagefile_0x0000000000110000 0x00110000 0x00111fff Pagefile Backed Memory - True - False -
reg.exe.mui 0x00120000 0x00128fff Memory Mapped File - False - False -
private_0x0000000000130000 0x00130000 0x00130fff Private Memory - True - False -
private_0x0000000000140000 0x00140000 0x00140fff Private Memory - True - False -
private_0x0000000000150000 0x00150000 0x0024ffff Private Memory - True - False -
private_0x00000000002f0000 0x002f0000 0x002fffff Private Memory - True - False -
pagefile_0x0000000000300000 0x00300000 0x003c7fff Pagefile Backed Memory - True - False -
pagefile_0x00000000003d0000 0x003d0000 0x004d0fff Pagefile Backed Memory - True - False -
sortdefault.nls 0x004e0000 0x007aefff Memory Mapped File - False - False -
kernelbase.dll.mui 0x007b0000 0x0086ffff Memory Mapped File - False - False -
reg.exe 0x00a00000 0x00a51fff Memory Mapped File - True - False -
pagefile_0x0000000000a60000 0x00a60000 0x0165ffff Pagefile Backed Memory - True - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0xf44
10 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10908525 True 1
Fn
Module Get Handle module_name = c:\windows\system32\reg.exe, base_address = 0xa00000 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, value_name = NTMGCGGUKus False 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run, value_name = NTMGCGGUKus, data = "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm", size = 242, type = REG_EXPAND_SZ True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
Process #17: attrib.exe
0 0
»
Information Value
ID #17
File Name c:\windows\system32\attrib.exe
Command Line attrib +h "C:\Users\2XC7u663GxWc\cqsFQOTqbmg\*.*"
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:00, Reason: Self Terminated
Monitor Duration 00:00:03
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xf48
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x F4C
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x0000000000130000 0x00130000 0x0016ffff Private Memory - True - False -
private_0x0000000000220000 0x00220000 0x0022ffff Private Memory - True - False -
private_0x00000000002d0000 0x002d0000 0x003cffff Private Memory - True - False -
pagefile_0x00000000003d0000 0x003d0000 0x00497fff Pagefile Backed Memory - True - False -
attrib.exe 0x00620000 0x00626fff Memory Mapped File - False - False -
ulib.dll 0x71f80000 0x71f9cfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Process #18: attrib.exe
0 0
»
Information Value
ID #18
File Name c:\windows\system32\attrib.exe
Command Line attrib +h "C:\Users\2XC7u663GxWc\cqsFQOTqbmg"
Initial Working Directory C:\Users\2XC7u663GxWc\Desktop\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:00:59, Reason: Self Terminated
Monitor Duration 00:00:02
Remark No high level activity detected in monitored regions
OS Process Information
»
Information Value
PID 0xf50
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x F54
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x0000000000170000 0x00170000 0x001affff Private Memory - True - False -
pagefile_0x00000000001b0000 0x001b0000 0x00277fff Pagefile Backed Memory - True - False -
private_0x0000000000360000 0x00360000 0x0045ffff Private Memory - True - False -
attrib.exe 0x00620000 0x00626fff Memory Mapped File - False - False -
private_0x0000000000800000 0x00800000 0x0080ffff Private Memory - True - False -
ulib.dll 0x71f80000 0x71f9cfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Process #19: javaw.exe
3499 6
»
Information Value
ID #19
File Name c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe
Command Line C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe -jar C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:00:57, Reason: Child Process
Unmonitor End Time: 00:01:21, Reason: Self Terminated
Monitor Duration 00:00:24
OS Process Information
»
Information Value
PID 0xf58
Parent PID 0xcc0 (c:\program files\java\jre7\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x F5C
0x F90
0x F94
0x F98
0x F9C
0x FA0
0x FA4
0x FA8
0x FB0
0x FAC
0x FB4
0x FF0
0x FF4
0x FF8
0x 90
0x 978
0x 92C
0x 9F4
0x 25C
0x 3F8
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
private_0x0000000000020000 0x00020000 0x00020fff Private Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x00187fff Pagefile Backed Memory - True - False -
private_0x0000000000190000 0x00190000 0x00190fff Private Memory - True - False -
tzres.dll 0x001a0000 0x001a0fff Memory Mapped File - False - False -
pagefile_0x00000000001a0000 0x001a0000 0x001a0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000001b0000 0x001b0000 0x001b1fff Pagefile Backed Memory - True - False -
pagefile_0x00000000001c0000 0x001c0000 0x001c6fff Pagefile Backed Memory - True - False -
private_0x00000000001d0000 0x001d0000 0x001dffff Private Memory - True - False -
javaw.exe 0x001e0000 0x0020efff Memory Mapped File - True - False -
private_0x0000000000210000 0x00210000 0x0025ffff Private Memory - True - False -
pagefile_0x0000000000260000 0x00260000 0x00360fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000370000 0x00370000 0x00371fff Pagefile Backed Memory - True - False -
private_0x0000000000380000 0x00380000 0x00380fff Private Memory - True - False -
private_0x0000000000390000 0x00390000 0x00390fff Private Memory - True - False -
3928 0x003a0000 0x003affff Memory Mapped File rw True True False
private_0x00000000003b0000 0x003b0000 0x0042ffff Private Memory - True - False -
private_0x0000000000430000 0x00430000 0x0043ffff Private Memory - True - False -
private_0x0000000000440000 0x00440000 0x0044ffff Private Memory - True - False -
private_0x0000000000450000 0x00450000 0x0054ffff Private Memory - True - False -
pagefile_0x0000000000550000 0x00550000 0x0114ffff Pagefile Backed Memory - True - False -
private_0x0000000001150000 0x01150000 0x0124ffff Private Memory - True - False -
private_0x0000000001150000 0x01150000 0x011fffff Private Memory - True - False -
private_0x0000000001200000 0x01200000 0x0122ffff Private Memory - True - False -
private_0x0000000001240000 0x01240000 0x0124ffff Private Memory - True - False -
private_0x0000000001250000 0x01250000 0x0134ffff Private Memory - True - False -
pagefile_0x0000000001350000 0x01350000 0x01742fff Pagefile Backed Memory - True - False -
private_0x0000000001750000 0x01750000 0x018effff Private Memory - True - False -
rsaenh.dll 0x01750000 0x0178bfff Memory Mapped File - False - False -
private_0x0000000001790000 0x01790000 0x017dffff Private Memory - True - False -
private_0x00000000017e0000 0x017e0000 0x018dffff Private Memory - True - False -
private_0x00000000018e0000 0x018e0000 0x018effff Private Memory - True - False -
private_0x00000000018f0000 0x018f0000 0x01adffff Private Memory - True - False -
private_0x00000000018f0000 0x018f0000 0x0194ffff Private Memory - True - False -
private_0x0000000001990000 0x01990000 0x019dffff Private Memory - True - False -
private_0x0000000001a30000 0x01a30000 0x01a7ffff Private Memory - True - False -
private_0x0000000001aa0000 0x01aa0000 0x01adffff Private Memory - True - False -
private_0x0000000001ae0000 0x01ae0000 0x03adffff Private Memory - True - False -
private_0x0000000003b00000 0x03b00000 0x03b4ffff Private Memory - True - False -
private_0x0000000003b50000 0x03b50000 0x03b9ffff Private Memory - True - False -
private_0x0000000003ba0000 0x03ba0000 0x03beffff Private Memory - True - False -
private_0x0000000003c30000 0x03c30000 0x03c7ffff Private Memory - True - False -
private_0x0000000003c80000 0x03c80000 0x03d0ffff Private Memory - True - False -
private_0x0000000003d50000 0x03d50000 0x03d9ffff Private Memory - True - False -
private_0x0000000003e00000 0x03e00000 0x03e4ffff Private Memory - True - False -
private_0x0000000003ec0000 0x03ec0000 0x03f0ffff Private Memory - True - False -
private_0x0000000003f10000 0x03f10000 0x0410ffff Private Memory - True - False -
sortdefault.nls 0x04110000 0x043defff Memory Mapped File - False - False -
private_0x00000000043e0000 0x043e0000 0x045cffff Private Memory - True - False -
private_0x00000000043e0000 0x043e0000 0x0458ffff Private Memory - True - False -
private_0x00000000043e0000 0x043e0000 0x0453ffff Private Memory - True - False -
private_0x00000000043e0000 0x043e0000 0x044dffff Private Memory - True - False -
private_0x0000000004500000 0x04500000 0x0453ffff Private Memory - True - False -
private_0x0000000004580000 0x04580000 0x0458ffff Private Memory - True - False -
private_0x0000000004590000 0x04590000 0x045cffff Private Memory - True - False -
private_0x00000000045d0000 0x045d0000 0x047bffff Private Memory - True - False -
kernelbase.dll.mui 0x045d0000 0x0468ffff Memory Mapped File - False - False -
private_0x00000000046a0000 0x046a0000 0x046effff Private Memory - True - False -
private_0x0000000004700000 0x04700000 0x0474ffff Private Memory - True - False -
private_0x00000000047b0000 0x047b0000 0x047bffff Private Memory - True - False -
private_0x00000000047c0000 0x047c0000 0x04bbffff Private Memory - True - False -
private_0x0000000004bc0000 0x04bc0000 0x053bffff Private Memory - True - False -
private_0x0000000005410000 0x05410000 0x0545ffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - True - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x38ccffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x3871ffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - True - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x390cffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x38f3ffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - True - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x394cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
jvm.dll 0x6acb0000 0x6b02ffff Memory Mapped File - True - False -
awt.dll 0x6cdc0000 0x6cf02fff Memory Mapped File - True - False -
msvcr100.dll 0x6cf10000 0x6cfcefff Memory Mapped File - True - False -
winmm.dll 0x70250000 0x70281fff Memory Mapped File - False - False -
pnrpnsp.dll 0x71760000 0x71771fff Memory Mapped File - False - False -
winrnr.dll 0x71780000 0x71787fff Memory Mapped File - False - False -
napinsp.dll 0x717a0000 0x717affff Memory Mapped File - False - False -
rasadhlp.dll 0x717b0000 0x717b5fff Memory Mapped File - False - False -
net.dll 0x71fa0000 0x71fb3fff Memory Mapped File - True - False -
sunec.dll 0x71fc0000 0x71fdffff Memory Mapped File - True - False -
nio.dll 0x720b0000 0x720befff Memory Mapped File - True - False -
zip.dll 0x720c0000 0x720d2fff Memory Mapped File - True - False -
java.dll 0x720e0000 0x720fffff Memory Mapped File - True - False -
verify.dll 0x72100000 0x7210bfff Memory Mapped File - True - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
fwpuclnt.dll 0x737d0000 0x73807fff Memory Mapped File - False - False -
winnsi.dll 0x738e0000 0x738e6fff Memory Mapped File - False - False -
iphlpapi.dll 0x738f0000 0x7390bfff Memory Mapped File - False - False -
nlaapi.dll 0x73a60000 0x73a6ffff Memory Mapped File - False - False -
comctl32.dll 0x73ee0000 0x7407dfff Memory Mapped File - False - False -
wsock32.dll 0x740b0000 0x740b6fff Memory Mapped File - False - False -
wshtcpip.dll 0x744e0000 0x744e4fff Memory Mapped File - False - False -
userenv.dll 0x745b0000 0x745c6fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
dnsapi.dll 0x74850000 0x74893fff Memory Mapped File - False - False -
wship6.dll 0x74980000 0x74985fff Memory Mapped File - False - False -
mswsock.dll 0x74990000 0x749cbfff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
profapi.dll 0x74f00000 0x74f0afff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
psapi.dll 0x76350000 0x76354fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory - True - False -
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 32 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
Threads
Thread 0xf5c
44 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:49:57 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10908307 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x7559418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x75591e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755976e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x75591f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 22, size_out = 22 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 1024, size_out = 1024 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 686 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x7559418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x75591e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755976e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x75591f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:49:57 (UTC) True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, base_address = 0x6acb0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_CreateJavaVM, address_out = 0x6ad78e70 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_GetDefaultJavaVMInitArgs, address_out = 0x6ad6e340 True 1
Fn
Thread 0xf90
2788 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Environment Get Environment String name = _ALT_JAVA_HOME_DIR False 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\verify.dll, base_address = 0x72100000 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.dll, base_address = 0x720e0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, address_out = 0x720e6fcf True 1
Fn
Environment Get Environment String name = JAVA_TOOL_OPTIONS False 1
Fn
Environment Get Environment String name = _JAVA_OPTIONS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\endorsed, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 2
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
File Create Directory C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\3928, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_DELETE_ON_CLOSE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\3928, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\3928, protection = PAGE_READWRITE, maximum_size = 65536 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\3928, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_ALL_ACCESS True 1
Fn
File Get Info type = file_type True 1
Fn
File Read size = 4096, size_out = 2190 True 1
Fn
Data
File Read size = 4096, size_out = 0 True 1
Fn
File Get Info type = file_type True 1
Fn
File Read size = 2416, size_out = 2416 True 1
Fn
Data
Module Create Mapping protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, size = 65536, size_out = 65536 True 1
Fn
Data
System Get Info type = Hardware Information True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 7, size_out = 7 True 1
Fn
Data
File Read size = 1781193, size_out = 1781193 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 709, size_out = 709 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 277, size_out = 277 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2305, size_out = 2305 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1022, size_out = 1022 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2882, size_out = 2882 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 104, size_out = 104 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 728, size_out = 728 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 345, size_out = 345 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 815, size_out = 815 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1105, size_out = 1105 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1761, size_out = 1761 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 514, size_out = 514 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 970, size_out = 970 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2589, size_out = 2589 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1008, size_out = 1008 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2004, size_out = 2004 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 2
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 669, size_out = 669 True 1
Fn
Data
File Read size = 8192, size_out = 829 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 829 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 962, size_out = 962 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 934, size_out = 934 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1720, size_out = 1720 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1012, size_out = 1012 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3028, size_out = 3028 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2976, size_out = 2976 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 672, size_out = 672 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1189, size_out = 1189 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2646, size_out = 2646 True 1
Fn
Data
File Read size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 966, size_out = 966 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 800, size_out = 800 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1280, size_out = 1280 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 609, size_out = 609 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 628, size_out = 628 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 328, size_out = 328 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 327, size_out = 327 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\management\usagetracker.properties, type = file_attributes False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 12212, size_out = 12212 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 748, size_out = 748 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6630, size_out = 6630 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3392, size_out = 3392 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 30105, size_out = 30105 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2563, size_out = 2563 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 476, size_out = 476 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2703, size_out = 2703 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 753, size_out = 753 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3690, size_out = 3690 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3361, size_out = 3361 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3599, size_out = 3599 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 260, size_out = 260 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1899, size_out = 1899 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 678, size_out = 678 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 100, size_out = 100 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1909, size_out = 1909 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 670, size_out = 670 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 762, size_out = 762 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 1
Fn
File Get Info type = time True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 30105, size_out = 30105 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 100, size_out = 100 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 100, size_out = 100 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 391, size_out = 391 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 452, size_out = 452 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 536, size_out = 536 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 521, size_out = 521 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 491, size_out = 491 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 506, size_out = 506 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 515, size_out = 515 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 361, size_out = 361 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 675, size_out = 675 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 451, size_out = 451 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 355, size_out = 355 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 299, size_out = 299 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 474, size_out = 474 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 655, size_out = 655 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 303, size_out = 303 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 335, size_out = 335 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 418, size_out = 418 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 430, size_out = 430 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 453, size_out = 453 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 555, size_out = 555 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 408, size_out = 408 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 477, size_out = 477 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 562, size_out = 562 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 394, size_out = 394 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 477, size_out = 477 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 462, size_out = 462 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 371, size_out = 371 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 231, size_out = 231 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 496, size_out = 496 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 691, size_out = 691 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 509, size_out = 509 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 580, size_out = 580 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 391, size_out = 391 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 496, size_out = 496 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 348, size_out = 348 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 802, size_out = 802 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1127, size_out = 1127 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib, type = file_attributes True 2
Fn
File Read size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 2190 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\meta-index, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:58 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 329, size_out = 329 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 383, size_out = 383 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 332, size_out = 332 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 348, size_out = 348 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 461, size_out = 461 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 570, size_out = 570 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5504, size_out = 5504 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 582, size_out = 582 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 535, size_out = 535 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 678, size_out = 678 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 315, size_out = 315 True 1
Fn
Data
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 6708, size_out = 6708 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 2
Fn
Data
File Read size = 1693, size_out = 1693 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1351, size_out = 1351 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = file_attributes True 1
Fn
File Read size = 8192, size_out = 8192 True 2
Fn
Data
File Read size = 8192, size_out = 1440 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 17824 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2345, size_out = 2345 True 1
Fn
Data
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 7, size_out = 7 True 1
Fn
Data
File Read size = 13694, size_out = 13694 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1056, size_out = 1056 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3940, size_out = 3940 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5672, size_out = 5672 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 844, size_out = 844 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1453, size_out = 1453 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 803, size_out = 803 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2601, size_out = 2601 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info type = time True 1
Fn
File Read size = 4, size_out = 4 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 1240, size_out = 1240 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2666, size_out = 2666 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 314, size_out = 314 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 951, size_out = 951 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 10594, size_out = 10594 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3882, size_out = 3882 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3549, size_out = 3549 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1381, size_out = 1381 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8211, size_out = 8211 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1075, size_out = 1075 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3695, size_out = 3695 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2117, size_out = 2117 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 346, size_out = 346 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 576, size_out = 576 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 24203, size_out = 24203 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 13092, size_out = 13092 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 623, size_out = 623 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3174, size_out = 3174 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2257, size_out = 2257 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1621, size_out = 1621 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2563, size_out = 2563 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2395, size_out = 2395 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 14258, size_out = 14258 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 853, size_out = 853 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 967, size_out = 967 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3914, size_out = 3914 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5828, size_out = 5828 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 12814, size_out = 12814 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4077, size_out = 4077 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2399, size_out = 2399 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2181, size_out = 2181 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 308, size_out = 308 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 381, size_out = 381 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 78, size_out = 78 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4556, size_out = 4556 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6732, size_out = 6732 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 732, size_out = 732 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 454, size_out = 454 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 457, size_out = 457 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 973, size_out = 973 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 310, size_out = 310 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2812, size_out = 2812 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 278, size_out = 278 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 131, size_out = 131 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3431, size_out = 3431 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 382, size_out = 382 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 281, size_out = 281 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5929, size_out = 5929 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6713, size_out = 6713 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3217, size_out = 3217 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 265, size_out = 265 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6705, size_out = 6705 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunec.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:59 (UTC) True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1434, size_out = 1434 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 454, size_out = 454 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5439, size_out = 5439 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 619, size_out = 619 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 10470, size_out = 10470 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 735, size_out = 735 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4170, size_out = 4170 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 817, size_out = 817 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2357, size_out = 2357 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 187, size_out = 187 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3665, size_out = 3665 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3856, size_out = 3856 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 333, size_out = 333 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info type = time True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\local_policy.jar, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2915, size_out = 2915 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 328, size_out = 328 True 1
Fn
Data
File Read size = 350, size_out = 350 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 160, size_out = 160 True 3
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 213, size_out = 213 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1319, size_out = 1319 True 1
Fn
Data
File Read size = 151, size_out = 151 True 1
Fn
Data
File Read size = 92, size_out = 92 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 1
Fn
Data
File Read size = 47, size_out = 47 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 115, size_out = 115 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 502, size_out = 502 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 807, size_out = 807 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 530, size_out = 530 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1987, size_out = 1987 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 706, size_out = 706 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 1
Fn
Data
File Read size = 3777, size_out = 3777 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3082, size_out = 3082 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4270, size_out = 4270 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8559, size_out = 8559 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6031, size_out = 6031 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:59 (UTC) True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _JNI_OnLoad@8, address_out = 0x71fa3379 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 671, size_out = 671 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1961, size_out = 1961 True 1
Fn
Data
DNS Get Hostname name_out = ZgW5tdPu True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3287, size_out = 3287 True 1
Fn
Data
DNS Resolve Name host = ZgW5tdPu, address_out = fe80:0000:0000:0000:5969:84a4:f9e2:1f2b, 192.168.0.60 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 383, size_out = 383 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3661, size_out = 3661 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 292, size_out = 292 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 389, size_out = 389 True 1
Fn
Data
File Read size = 411, size_out = 411 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 194, size_out = 194 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1318, size_out = 1318 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 153, size_out = 153 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 209, size_out = 209 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 883, size_out = 883 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 994, size_out = 994 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 780, size_out = 780 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 206, size_out = 206 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 533, size_out = 533 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 775, size_out = 775 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 301, size_out = 301 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1137, size_out = 1137 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1486, size_out = 1486 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1009, size_out = 1009 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1052, size_out = 1052 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 269, size_out = 269 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1438, size_out = 1438 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2684, size_out = 2684 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 157, size_out = 157 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 902, size_out = 902 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1516, size_out = 1516 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 925, size_out = 925 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1403, size_out = 1403 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 684, size_out = 684 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2171, size_out = 2171 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1421, size_out = 1421 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 694, size_out = 694 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 171, size_out = 171 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 814, size_out = 814 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 608, size_out = 608 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 677, size_out = 677 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1343, size_out = 1343 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 541, size_out = 541 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2912, size_out = 2912 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1249, size_out = 1249 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1311, size_out = 1311 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 265, size_out = 265 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1605, size_out = 1605 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 557, size_out = 557 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 173, size_out = 173 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2789, size_out = 2789 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 230, size_out = 230 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1133, size_out = 1133 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 321, size_out = 321 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 190, size_out = 190 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 1
Fn
Data
File Read size = 3185, size_out = 3185 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4522, size_out = 4522 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 978, size_out = 978 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 672, size_out = 672 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 839, size_out = 839 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1309, size_out = 1309 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1312, size_out = 1312 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 696, size_out = 696 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3200, size_out = 3200 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 803, size_out = 803 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 207, size_out = 207 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 823, size_out = 823 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 824, size_out = 824 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 349, size_out = 349 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2972, size_out = 2972 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2977, size_out = 2977 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 611, size_out = 611 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 668, size_out = 668 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 283, size_out = 283 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1118, size_out = 1118 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 834, size_out = 834 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 769, size_out = 769 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1478, size_out = 1478 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1298, size_out = 1298 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1655, size_out = 1655 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
For performance reasons, the remaining 1672 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xf94
9 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:49:59 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 3
Fn
Thread 0xf98
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xf9c
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ref_Finalizer_invokeFinalizeMethod@12, address_out = 0x720e207c True 1
Fn
Thread 0xfa0
5 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 541, size_out = 541 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfa4
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Mutex Create - True 1
Fn
Thread 0xfa8
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfb0
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfac
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xff0
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xff4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xff8
39 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x6ce52210 True 1
Fn
Module Load module_name = COMCTL32.dll, base_address = 0x73ee0000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x73f009ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x76b4f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x76b4ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x76b5544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x754f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x754f6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x76b55421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x76b4ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x76b5507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x76b4e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6ce51da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x7637efd7 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 569, size_out = 569 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 333, size_out = 333 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x76b5634a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address_out = 0x76b4b712 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostMessageW, address_out = 0x76b5447b True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address_out = 0x76b4abe1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address_out = 0x76b4b308 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address_out = 0x7637eba1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetMessageW, address_out = 0x76b5cde8 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = IsWindow, address_out = 0x76b553ba True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address_out = 0x76b4b2f4 True 1
Fn
Thread 0x90
302 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:01 (UTC) True 1
Fn
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 706, size_out = 706 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 448, size_out = 448 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4013, size_out = 4013 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1566, size_out = 1566 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 402, size_out = 402 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1366, size_out = 1366 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 9311, size_out = 9311 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3572, size_out = 3572 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1619, size_out = 1619 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2404, size_out = 2404 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3013, size_out = 3013 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1708, size_out = 1708 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2879, size_out = 2879 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1285, size_out = 1285 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1398, size_out = 1398 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1090, size_out = 1090 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3789, size_out = 3789 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 436, size_out = 436 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 792, size_out = 792 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 384, size_out = 384 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 78, size_out = 78 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1217, size_out = 1217 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 480, size_out = 480 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 622, size_out = 622 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 76, size_out = 76 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 527, size_out = 527 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4051, size_out = 4051 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7991, size_out = 7991 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 704, size_out = 704 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8401, size_out = 8401 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2096, size_out = 2096 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2691, size_out = 2691 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, os_pid = 0x110, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_terminateProcess@16, address_out = 0x720e8e7c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_delete0@12, address_out = 0x720ea507 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, size = 281 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, os_pid = 0x754, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes True 1
Fn
File Create filename = C:\Windows\System32\test.txt, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1396, size_out = 1396 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 582, size_out = 582 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 46400, size_out = 46400 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 263, size_out = 263 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 357, size_out = 357 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5472, size_out = 5472 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3241, size_out = 3241 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 784, size_out = 784 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1886, size_out = 1886 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5529, size_out = 5529 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x71fa157c True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1188, size_out = 1188 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 213, size_out = 213 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x71fa214a True 1
Fn
Module Load module_name = IPHLPAPI.DLL, base_address = 0x738f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIfTable, address_out = 0x738fae94 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetFriendlyIfIndex, address_out = 0x738fd855 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIpAddrTable, address_out = 0x738f9bb0 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetAdaptersAddresses, address_out = 0x738f6a4d True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 878, size_out = 878 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7520, size_out = 7520 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8446, size_out = 8446 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, base_address = 0x6da40000 True 1
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x6da42194 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5830, size_out = 5830 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1929, size_out = 1929 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x6da41e06 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x6da41e8a True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 519, size_out = 519 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 855, size_out = 855 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 413, size_out = 413 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 300, size_out = 300 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 152, size_out = 152 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1206, size_out = 1206 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x6da42a5b True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x6da4230d True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7192, size_out = 7192 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 536, size_out = 536 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 22580, size_out = 22580 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 325, size_out = 325 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2388, size_out = 2388 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1746, size_out = 1746 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 845, size_out = 845 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 14934, size_out = 14934 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 322, size_out = 322 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1032, size_out = 1032 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 773, size_out = 773 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 122, size_out = 122 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt, type = size, size_out = 47 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg, type = file_attributes True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\nccJQMiokAP, type = file_attributes False 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_createDirectory@12, address_out = 0x720ea812 True 1
Fn
File Create Directory C:\Users\2XC7u663GxWc\cqsFQOTqbmg\nccJQMiokAP True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\nccJQMiokAP, type = file_attributes True 3
Fn
Thread 0x978
4 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:06 (UTC) True 2
Fn
Thread 0x92c
287 1
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 26461, size_out = 26461 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4540, size_out = 4540 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1995, size_out = 1995 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:06 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1261, size_out = 1261 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4115, size_out = 4115 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x71fa6667 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2598, size_out = 2598 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 11029, size_out = 11029 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 296, size_out = 296 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1028, size_out = 1028 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 17440, size_out = 17440 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3033, size_out = 3033 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 861, size_out = 861 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2660, size_out = 2660 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1444, size_out = 1444 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1192, size_out = 1192 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:06 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7071, size_out = 7071 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2038, size_out = 2038 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2049, size_out = 2049 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1627, size_out = 1627 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8760, size_out = 8760 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3164, size_out = 3164 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2552, size_out = 2552 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1600, size_out = 1600 True 1
Fn
Data
File Read size = 109, size_out = 109 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 235, size_out = 235 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2863, size_out = 2863 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 443, size_out = 443 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 837, size_out = 837 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3196, size_out = 3196 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = time True 1
Fn
File Read size = 1262, size_out = 1262 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1812, size_out = 1812 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 240, size_out = 240 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1434, size_out = 1434 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2863, size_out = 2863 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 390, size_out = 390 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1989, size_out = 1989 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 837, size_out = 837 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 734, size_out = 734 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 235, size_out = 235 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:06 (UTC) True 2
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5122, size_out = 5122 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 285, size_out = 285 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 889, size_out = 889 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3271, size_out = 3271 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 496, size_out = 496 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1812, size_out = 1812 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 302, size_out = 302 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 23927, size_out = 23927 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1227, size_out = 1227 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 761, size_out = 761 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 107, size_out = 107 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2146, size_out = 2146 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 975, size_out = 975 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2114, size_out = 2114 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3293, size_out = 3293 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 634, size_out = 634 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 725, size_out = 725 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 859, size_out = 859 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 745, size_out = 745 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1326, size_out = 1326 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4319, size_out = 4319 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 595, size_out = 595 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 626, size_out = 626 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 763, size_out = 763 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 2191, size_out = 2191 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 913, size_out = 913 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 852, size_out = 852 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1269, size_out = 1269 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 404, size_out = 404 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, base_address = 0x6b6c0000 True 1
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1399, size_out = 1399 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3618, size_out = 3618 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1507, size_out = 1507 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8099, size_out = 8099 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 964, size_out = 964 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1312, size_out = 1312 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5799, size_out = 5799 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x71fa66ab True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 686, size_out = 686 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = size, size_out = 3070 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3605, size_out = 3605 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x71fa6793 True 1
Fn
Thread 0x9f4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0x25c
3 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:18 (UTC) True 1
Fn
Thread 0x3f8
7 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x6ce50ac0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SendMessageW, address_out = 0x76b55539 True 1
Fn
Process #20: java.exe
2821 15
»
Information Value
ID #20
File Name c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe
Command Line C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.080316539076114361006181509658991106.class
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:00, Reason: Child Process
Unmonitor End Time: 00:01:20, Reason: Self Terminated
Monitor Duration 00:00:20
OS Process Information
»
Information Value
PID 0xfb8
Parent PID 0xf58 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x FBC
0x FCC
0x FD0
0x FD4
0x FD8
0x FE4
0x FDC
0x FE0
0x FEC
0x FE8
0x FFC
0x 854
0x 124
0x 150
0x 874
0x 44C
0x 7FC
0x 930
0x 934
0x 938
0x 940
0x A00
0x 9E8
0x 9F0
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory - True - False -
private_0x00000000000d0000 0x000d0000 0x000d0fff Private Memory - True - False -
tzres.dll 0x000e0000 0x000e0fff Memory Mapped File - False - False -
pagefile_0x00000000000e0000 0x000e0000 0x000e0fff Pagefile Backed Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000fffff Private Memory - True - False -
pagefile_0x0000000000100000 0x00100000 0x00101fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000110000 0x00110000 0x00116fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000120000 0x00120000 0x00121fff Pagefile Backed Memory - True - False -
private_0x0000000000130000 0x00130000 0x0016ffff Private Memory - True - False -
private_0x0000000000170000 0x00170000 0x00170fff Private Memory - True - False -
private_0x0000000000180000 0x00180000 0x00180fff Private Memory - True - False -
4024 0x00190000 0x0019ffff Memory Mapped File rw True True False
private_0x00000000001a0000 0x001a0000 0x001effff Private Memory - True - False -
pagefile_0x00000000001f0000 0x001f0000 0x002b7fff Pagefile Backed Memory - True - False -
pagefile_0x00000000002c0000 0x002c0000 0x003c0fff Pagefile Backed Memory - True - False -
private_0x00000000003d0000 0x003d0000 0x004cffff Private Memory - True - False -
private_0x00000000004d0000 0x004d0000 0x0061ffff Private Memory - True - False -
private_0x00000000004d0000 0x004d0000 0x005cffff Private Memory - True - False -
private_0x00000000005d0000 0x005d0000 0x005fffff Private Memory - True - False -
private_0x0000000000600000 0x00600000 0x0060ffff Private Memory - True - False -
private_0x0000000000610000 0x00610000 0x0061ffff Private Memory - True - False -
pagefile_0x0000000000620000 0x00620000 0x00a12fff Pagefile Backed Memory - True - False -
private_0x0000000000a20000 0x00a20000 0x00b1ffff Private Memory - True - False -
private_0x0000000000b20000 0x00b20000 0x00b2ffff Private Memory - True - False -
private_0x0000000000b30000 0x00b30000 0x00b3ffff Private Memory - True - False -
private_0x0000000000b40000 0x00b40000 0x00bbffff Private Memory - True - False -
private_0x0000000000bc0000 0x00bc0000 0x00c1ffff Private Memory - True - False -
pagefile_0x0000000000c20000 0x00c20000 0x00c20fff Pagefile Backed Memory - True - False -
private_0x0000000000c50000 0x00c50000 0x00c9ffff Private Memory - True - False -
private_0x0000000000ca0000 0x00ca0000 0x00d4ffff Private Memory - True - False -
rsaenh.dll 0x00d50000 0x00d8bfff Memory Mapped File - False - False -
rpcss.dll 0x00d50000 0x00dabfff Memory Mapped File - False - False -
private_0x0000000000db0000 0x00db0000 0x00dfffff Private Memory - True - False -
private_0x0000000000e60000 0x00e60000 0x00eaffff Private Memory - True - False -
java.exe 0x00eb0000 0x00edefff Memory Mapped File - True - False -
pagefile_0x0000000000ee0000 0x00ee0000 0x01adffff Pagefile Backed Memory - True - False -
private_0x0000000001ae0000 0x01ae0000 0x03adffff Private Memory - True - False -
private_0x0000000003b20000 0x03b20000 0x03b6ffff Private Memory - True - False -
private_0x0000000003b70000 0x03b70000 0x03bbffff Private Memory - True - False -
private_0x0000000003c00000 0x03c00000 0x03c4ffff Private Memory - True - False -
private_0x0000000003c80000 0x03c80000 0x03ccffff Private Memory - True - False -
private_0x0000000003cd0000 0x03cd0000 0x03d1ffff Private Memory - True - False -
private_0x0000000003d40000 0x03d40000 0x03d8ffff Private Memory - True - False -
private_0x0000000003d90000 0x03d90000 0x03f8ffff Private Memory - True - False -
sortdefault.nls 0x03f90000 0x0425efff Memory Mapped File - False - False -
private_0x0000000004260000 0x04260000 0x0441ffff Private Memory - True - False -
private_0x0000000004260000 0x04260000 0x0432ffff Private Memory - True - False -
private_0x0000000004260000 0x04260000 0x042cffff Private Memory - True - False -
private_0x00000000042f0000 0x042f0000 0x0432ffff Private Memory - True - False -
private_0x00000000043e0000 0x043e0000 0x0441ffff Private Memory - True - False -
private_0x0000000004420000 0x04420000 0x045effff Private Memory - True - False -
private_0x0000000004460000 0x04460000 0x044affff Private Memory - True - False -
private_0x00000000044b0000 0x044b0000 0x045affff Private Memory - True - False -
private_0x00000000045e0000 0x045e0000 0x045effff Private Memory - True - False -
private_0x00000000045f0000 0x045f0000 0x047cffff Private Memory - True - False -
kernelbase.dll.mui 0x045f0000 0x046affff Memory Mapped File - False - False -
private_0x00000000046d0000 0x046d0000 0x0471ffff Private Memory - True - False -
private_0x00000000047c0000 0x047c0000 0x047cffff Private Memory - True - False -
private_0x00000000047d0000 0x047d0000 0x049affff Private Memory - True - False -
private_0x0000000004800000 0x04800000 0x0484ffff Private Memory - True - False -
private_0x00000000048d0000 0x048d0000 0x0491ffff Private Memory - True - False -
private_0x0000000004920000 0x04920000 0x0496ffff Private Memory - True - False -
private_0x0000000004970000 0x04970000 0x049affff Private Memory - True - False -
pagefile_0x00000000049b0000 0x049b0000 0x04a8efff Pagefile Backed Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - True - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - True - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - True - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
jvm.dll 0x6acb0000 0x6b02ffff Memory Mapped File - True - False -
awt.dll 0x6cdc0000 0x6cf02fff Memory Mapped File - True - False -
msvcr100.dll 0x6cf10000 0x6cfcefff Memory Mapped File - True - False -
winmm.dll 0x70250000 0x70281fff Memory Mapped File - False - False -
pnrpnsp.dll 0x71760000 0x71771fff Memory Mapped File - False - False -
winrnr.dll 0x71780000 0x71787fff Memory Mapped File - False - False -
napinsp.dll 0x717a0000 0x717affff Memory Mapped File - False - False -
rasadhlp.dll 0x717b0000 0x717b5fff Memory Mapped File - False - False -
net.dll 0x71fa0000 0x71fb3fff Memory Mapped File - True - False -
sunec.dll 0x71fc0000 0x71fdffff Memory Mapped File - True - False -
nio.dll 0x720b0000 0x720befff Memory Mapped File - True - False -
zip.dll 0x720c0000 0x720d2fff Memory Mapped File - True - False -
java.dll 0x720e0000 0x720fffff Memory Mapped File - True - False -
verify.dll 0x72100000 0x7210bfff Memory Mapped File - True - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
fwpuclnt.dll 0x737d0000 0x73807fff Memory Mapped File - False - False -
winnsi.dll 0x738e0000 0x738e6fff Memory Mapped File - False - False -
iphlpapi.dll 0x738f0000 0x7390bfff Memory Mapped File - False - False -
nlaapi.dll 0x73a60000 0x73a6ffff Memory Mapped File - False - False -
comctl32.dll 0x73ee0000 0x7407dfff Memory Mapped File - False - False -
wsock32.dll 0x740b0000 0x740b6fff Memory Mapped File - False - False -
wshtcpip.dll 0x744e0000 0x744e4fff Memory Mapped File - False - False -
userenv.dll 0x745b0000 0x745c6fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
dnsapi.dll 0x74850000 0x74893fff Memory Mapped File - False - False -
wship6.dll 0x74980000 0x74985fff Memory Mapped File - False - False -
mswsock.dll 0x74990000 0x749cbfff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
profapi.dll 0x74f00000 0x74f0afff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
psapi.dll 0x76350000 0x76354fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
private_0x000000007ffae000 0x7ffae000 0x7ffaefff Private Memory - True - False -
private_0x000000007ffaf000 0x7ffaf000 0x7ffaffff Private Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd3000 0x7ffd3000 0x7ffd3fff Private Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 28 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
C:\Users\2XC7u663GxWc\fUTkALeaTxM\ID.txt 0.05 KB MD5: 473d5ea6460d84e1c44532bf39d48eb7
SHA1: c760d009877410051d803f625211fd027445d1c8
SHA256: 9f32e41ce1b7a69787cd3886274f9e8c8a910607a0687b3d3cf965cef60d2109
SSDeep: 3:YwwAHWKIDdIRRKu9hASMi:YwwAHWKIDdsEKhv
False
Threads
Thread 0xfbc
37 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10910522 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x7559418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x75591e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755976e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x75591f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
File Get Info type = file_type True 1
Fn
File Read size = 22, size_out = 22 True 1
Fn
Data
File Read size = 1024, size_out = 1024 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
File Get Info type = file_type True 1
Fn
File Read size = 4096, size_out = 686 True 1
Fn
Data
File Read size = 4096, size_out = 0 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, base_address = 0x6acb0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_CreateJavaVM, address_out = 0x6ad78e70 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_GetDefaultJavaVMInitArgs, address_out = 0x6ad6e340 True 1
Fn
Thread 0xfcc
1969 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Environment Get Environment String name = _ALT_JAVA_HOME_DIR False 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\verify.dll, base_address = 0x72100000 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.dll, base_address = 0x720e0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, address_out = 0x720e6fcf True 1
Fn
Environment Get Environment String name = JAVA_TOOL_OPTIONS False 1
Fn
Environment Get Environment String name = _JAVA_OPTIONS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\endorsed, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 2
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x752a7a8b True 1
Fn
File Create Directory C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\4024, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_DELETE_ON_CLOSE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\4024, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\4024, protection = PAGE_READWRITE, maximum_size = 65536 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\4024, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, desired_access = FILE_MAP_ALL_ACCESS True 1
Fn
File Get Info type = file_type True 2
Fn
File Read size = 2416, size_out = 2416 True 1
Fn
Data
System Get Info type = Hardware Information True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 7, size_out = 7 True 1
Fn
Data
File Read size = 1781193, size_out = 1781193 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 709, size_out = 709 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 277, size_out = 277 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2305, size_out = 2305 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1022, size_out = 1022 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2882, size_out = 2882 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 104, size_out = 104 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 728, size_out = 728 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 345, size_out = 345 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 815, size_out = 815 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1105, size_out = 1105 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1761, size_out = 1761 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 514, size_out = 514 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 970, size_out = 970 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2589, size_out = 2589 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1008, size_out = 1008 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2004, size_out = 2004 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 2
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 669, size_out = 669 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 829 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 962, size_out = 962 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 934, size_out = 934 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1720, size_out = 1720 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1012, size_out = 1012 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3028, size_out = 3028 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2976, size_out = 2976 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 672, size_out = 672 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1189, size_out = 1189 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2646, size_out = 2646 True 1
Fn
Data
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 966, size_out = 966 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 800, size_out = 800 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1280, size_out = 1280 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 609, size_out = 609 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 628, size_out = 628 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 328, size_out = 328 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 327, size_out = 327 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 12212, size_out = 12212 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 748, size_out = 748 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6630, size_out = 6630 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3392, size_out = 3392 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 6113, size_out = 6113 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2563, size_out = 2563 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 476, size_out = 476 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2703, size_out = 2703 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 753, size_out = 753 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3690, size_out = 3690 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3361, size_out = 3361 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3599, size_out = 3599 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 260, size_out = 260 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1899, size_out = 1899 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 678, size_out = 678 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1909, size_out = 1909 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 670, size_out = 670 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 762, size_out = 762 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 6113, size_out = 6113 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 2
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 263, size_out = 263 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 2
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 729, size_out = 729 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 17, size_out = 17 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 243, size_out = 243 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 315, size_out = 315 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 437, size_out = 437 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 439, size_out = 439 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 342, size_out = 342 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 802, size_out = 802 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1127, size_out = 1127 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 1
Fn
File Read size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 2190 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:00 (UTC) True 15
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1468, size_out = 1468 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1486, size_out = 1486 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 258, size_out = 258 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2351, size_out = 2351 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 877, size_out = 877 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 645, size_out = 645 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6444, size_out = 6444 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1453, size_out = 1453 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 513, size_out = 513 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4556, size_out = 4556 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 17824 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2345, size_out = 2345 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 7, size_out = 7 True 1
Fn
Data
File Read size = 13694, size_out = 13694 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1056, size_out = 1056 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3940, size_out = 3940 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5672, size_out = 5672 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 844, size_out = 844 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 803, size_out = 803 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2601, size_out = 2601 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6732, size_out = 6732 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 732, size_out = 732 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 454, size_out = 454 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 78, size_out = 78 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 457, size_out = 457 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 973, size_out = 973 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 308, size_out = 308 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 381, size_out = 381 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 310, size_out = 310 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3431, size_out = 3431 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 382, size_out = 382 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 281, size_out = 281 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 131, size_out = 131 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5929, size_out = 5929 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 405, size_out = 405 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 17, size_out = 17 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 182, size_out = 182 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 258, size_out = 258 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 354, size_out = 354 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 645, size_out = 645 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 17, size_out = 17 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 380, size_out = 380 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 17, size_out = 17 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 512, size_out = 512 True 1
Fn
Data
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 6708, size_out = 6708 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 2
Fn
Data
File Read size = 1693, size_out = 1693 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1351, size_out = 1351 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 1240, size_out = 1240 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2666, size_out = 2666 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 314, size_out = 314 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 951, size_out = 951 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 10594, size_out = 10594 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3882, size_out = 3882 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3549, size_out = 3549 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1381, size_out = 1381 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8211, size_out = 8211 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1075, size_out = 1075 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3695, size_out = 3695 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2117, size_out = 2117 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 346, size_out = 346 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 576, size_out = 576 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 24203, size_out = 24203 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 13092, size_out = 13092 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 623, size_out = 623 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3174, size_out = 3174 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2257, size_out = 2257 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1621, size_out = 1621 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2563, size_out = 2563 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2395, size_out = 2395 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 14258, size_out = 14258 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 853, size_out = 853 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 967, size_out = 967 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3914, size_out = 3914 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5828, size_out = 5828 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 12814, size_out = 12814 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4077, size_out = 4077 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2399, size_out = 2399 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2181, size_out = 2181 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2812, size_out = 2812 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 278, size_out = 278 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6713, size_out = 6713 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:01 (UTC) True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1434, size_out = 1434 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 454, size_out = 454 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5439, size_out = 5439 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 619, size_out = 619 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 10470, size_out = 10470 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 735, size_out = 735 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4170, size_out = 4170 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 817, size_out = 817 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2357, size_out = 2357 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 187, size_out = 187 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3665, size_out = 3665 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3856, size_out = 3856 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 333, size_out = 333 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Get Info type = time True 1
Fn
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2915, size_out = 2915 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 328, size_out = 328 True 1
Fn
Data
File Read size = 350, size_out = 350 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 160, size_out = 160 True 3
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 213, size_out = 213 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1319, size_out = 1319 True 1
Fn
Data
File Read size = 151, size_out = 151 True 1
Fn
Data
File Read size = 92, size_out = 92 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 1
Fn
Data
File Read size = 47, size_out = 47 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 115, size_out = 115 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 502, size_out = 502 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 807, size_out = 807 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 530, size_out = 530 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1987, size_out = 1987 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 706, size_out = 706 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4096, size_out = 4096 True 1
Fn
Data
File Read size = 3777, size_out = 3777 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3082, size_out = 3082 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4270, size_out = 4270 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8559, size_out = 8559 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6031, size_out = 6031 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:01 (UTC) True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _JNI_OnLoad@8, address_out = 0x71fa3379 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 671, size_out = 671 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1961, size_out = 1961 True 1
Fn
Data
DNS Get Hostname name_out = ZgW5tdPu True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3287, size_out = 3287 True 1
Fn
Data
DNS Resolve Name host = ZgW5tdPu, address_out = fe80:0000:0000:0000:5969:84a4:f9e2:1f2b, 192.168.0.60 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 383, size_out = 383 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3661, size_out = 3661 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 292, size_out = 292 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 128, size_out = 128 True 1
Fn
Data
File Read size = 389, size_out = 389 True 1
Fn
Data
File Read size = 411, size_out = 411 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 194, size_out = 194 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1318, size_out = 1318 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 153, size_out = 153 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 209, size_out = 209 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 883, size_out = 883 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 994, size_out = 994 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 780, size_out = 780 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 206, size_out = 206 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 533, size_out = 533 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 775, size_out = 775 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 301, size_out = 301 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3596, size_out = 3596 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3529, size_out = 3529 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1137, size_out = 1137 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1486, size_out = 1486 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1009, size_out = 1009 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1052, size_out = 1052 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 269, size_out = 269 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1438, size_out = 1438 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2684, size_out = 2684 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 157, size_out = 157 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 902, size_out = 902 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1516, size_out = 1516 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 925, size_out = 925 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1403, size_out = 1403 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 684, size_out = 684 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2171, size_out = 2171 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1421, size_out = 1421 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 694, size_out = 694 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 171, size_out = 171 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 814, size_out = 814 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 608, size_out = 608 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 677, size_out = 677 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1343, size_out = 1343 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 541, size_out = 541 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2912, size_out = 2912 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1249, size_out = 1249 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1311, size_out = 1311 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 265, size_out = 265 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1605, size_out = 1605 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 557, size_out = 557 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 173, size_out = 173 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2789, size_out = 2789 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 230, size_out = 230 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1133, size_out = 1133 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 321, size_out = 321 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 190, size_out = 190 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 1
Fn
Data
File Read size = 3185, size_out = 3185 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4522, size_out = 4522 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 978, size_out = 978 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 672, size_out = 672 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 839, size_out = 839 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1309, size_out = 1309 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1312, size_out = 1312 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 696, size_out = 696 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3200, size_out = 3200 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 803, size_out = 803 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 207, size_out = 207 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 823, size_out = 823 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 824, size_out = 824 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 349, size_out = 349 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2972, size_out = 2972 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2977, size_out = 2977 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 611, size_out = 611 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 668, size_out = 668 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 283, size_out = 283 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1118, size_out = 1118 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 834, size_out = 834 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 769, size_out = 769 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1478, size_out = 1478 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1298, size_out = 1298 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1655, size_out = 1655 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 984, size_out = 984 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3278, size_out = 3278 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1137, size_out = 1137 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 833, size_out = 833 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1450, size_out = 1450 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1081, size_out = 1081 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 735, size_out = 735 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 349, size_out = 349 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 550, size_out = 550 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 922, size_out = 922 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5457, size_out = 5457 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1143, size_out = 1143 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2597, size_out = 2597 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 325, size_out = 325 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 271, size_out = 271 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1084, size_out = 1084 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4495, size_out = 4495 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1404, size_out = 1404 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5963, size_out = 5963 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1218, size_out = 1218 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 666, size_out = 666 True 1
Fn
Data
File Read size = 2371, size_out = 2371 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3665, size_out = 3665 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1686, size_out = 1686 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1029, size_out = 1029 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 306, size_out = 306 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 978, size_out = 978 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 1
Fn
Data
File Read size = 1459, size_out = 1459 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 282, size_out = 282 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read size = 6135, size_out = 6135 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8192, size_out = 8192 True 26
Fn
Data
File Read size = 5053, size_out = 5053 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 258, size_out = 258 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1470, size_out = 1470 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 354, size_out = 354 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1468, size_out = 1468 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 258, size_out = 258 True 1
Fn
Data
File Read size = 3, size_out = 3 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 263, size_out = 263 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 455, size_out = 455 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 617, size_out = 617 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 580, size_out = 580 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 463, size_out = 463 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 405, size_out = 405 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 332, size_out = 332 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 481, size_out = 481 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 593, size_out = 593 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 439, size_out = 439 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 606, size_out = 606 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 729, size_out = 729 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 390, size_out = 390 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 367, size_out = 367 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 315, size_out = 315 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 258, size_out = 258 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 347, size_out = 347 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 490, size_out = 490 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 383, size_out = 383 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 342, size_out = 342 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 346, size_out = 346 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 168, size_out = 168 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 645, size_out = 645 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 212, size_out = 212 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 437, size_out = 437 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 205, size_out = 205 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 512, size_out = 512 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 380, size_out = 380 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 182, size_out = 182 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 243, size_out = 243 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 189, size_out = 189 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 169, size_out = 169 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 161, size_out = 161 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 281, size_out = 281 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 274, size_out = 274 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1989, size_out = 1989 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
For performance reasons, the remaining 840 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0xfd0
52 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:01 (UTC) True 4
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:05 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:08 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:11 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:14 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:18 (UTC) True 9
Fn
Thread 0xfd4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfd8
31 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ref_Finalizer_invokeFinalizeMethod@12, address_out = 0x720e207c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_closeHandle@16, address_out = 0x720e8e8b True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:08 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:11 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:14 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:18 (UTC) True 7
Fn
Thread 0xfe4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfdc
5 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 541, size_out = 541 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0xfe0
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Mutex Create - True 1
Fn
Thread 0xfec
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
Thread 0xfe8
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0x854
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0x124
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0x150
39 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x6ce52210 True 1
Fn
Module Load module_name = COMCTL32.dll, base_address = 0x73ee0000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x73f009ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x76b4f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x76b4ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x76b5544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x754f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x754f6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x76b55421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x76b4ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x76b5507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x76b4e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6ce51da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x7637efd7 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 569, size_out = 569 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 333, size_out = 333 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x76b5634a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = EnumThreadWindows, address_out = 0x76b4b712 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostMessageW, address_out = 0x76b5447b True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CallNextHookEx, address_out = 0x76b4abe1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PostQuitMessage, address_out = 0x76b4b308 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleUninitialize, address_out = 0x7637eba1 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetMessageW, address_out = 0x76b5cde8 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = IsWindow, address_out = 0x76b553ba True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DestroyWindow, address_out = 0x76b4b2f4 True 1
Fn
Thread 0x874
350 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 16, size_out = 16 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 390, size_out = 390 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 448, size_out = 448 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4013, size_out = 4013 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1566, size_out = 1566 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 402, size_out = 402 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1366, size_out = 1366 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 9311, size_out = 9311 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3572, size_out = 3572 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1619, size_out = 1619 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2404, size_out = 2404 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3013, size_out = 3013 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1708, size_out = 1708 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2879, size_out = 2879 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1285, size_out = 1285 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1398, size_out = 1398 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1090, size_out = 1090 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3789, size_out = 3789 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 436, size_out = 436 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 792, size_out = 792 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 384, size_out = 384 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 78, size_out = 78 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1217, size_out = 1217 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 480, size_out = 480 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 622, size_out = 622 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 76, size_out = 76 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 527, size_out = 527 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4051, size_out = 4051 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7991, size_out = 7991 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 704, size_out = 704 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8401, size_out = 8401 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2096, size_out = 2096 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2691, size_out = 2691 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1111, size_out = 1111 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1664, size_out = 1664 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_createFileExclusively@12, address_out = 0x720ea467 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileOutputStream_open@16, address_out = 0x720e1fe4 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileOutputStream_writeBytes@24, address_out = 0x720e203c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileOutputStream_close0@8, address_out = 0x720e2063 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 6028, size_out = 6028 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7832, size_out = 7832 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 382, size_out = 382 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_getStillActive@8, address_out = 0x720e8e39 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5512, size_out = 5512 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 949, size_out = 949 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1167, size_out = 1167 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessEnvironment_environmentBlock@8, address_out = 0x720e274a True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1731, size_out = 1731 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1427, size_out = 1427 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1429, size_out = 1429 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_create@28, address_out = 0x720e8a87 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, os_pid = 0x400, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1873, size_out = 1873 True 1
Fn
Data
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_terminateProcess@16, address_out = 0x720e8e7c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_delete0@12, address_out = 0x720ea507 True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, size = 281 True 1
Fn
Data
System Get Info type = Operating System True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, os_pid = 0x588, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes True 1
Fn
File Create filename = C:\Windows\System32\test.txt, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1396, size_out = 1396 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 582, size_out = 582 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 46400, size_out = 46400 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 263, size_out = 263 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 357, size_out = 357 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5472, size_out = 5472 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3241, size_out = 3241 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 784, size_out = 784 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1886, size_out = 1886 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5529, size_out = 5529 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_NetworkInterface_init@8, address_out = 0x71fa157c True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1188, size_out = 1188 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 213, size_out = 213 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_NetworkInterface_getAll@8, address_out = 0x71fa214a True 1
Fn
Module Load module_name = IPHLPAPI.DLL, base_address = 0x738f0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIfTable, address_out = 0x738fae94 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetFriendlyIfIndex, address_out = 0x738fd855 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIpAddrTable, address_out = 0x738f9bb0 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetAdaptersAddresses, address_out = 0x738f6a4d True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 878, size_out = 878 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7520, size_out = 7520 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8446, size_out = 8446 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, base_address = 0x6da40000 True 1
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x6da42194 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5830, size_out = 5830 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1929, size_out = 1929 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_sun_management_VMManagementImpl_getVersion0@8, address_out = 0x6da41e06 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_sun_management_VMManagementImpl_initOptionalSupportFields@8, address_out = 0x6da41e8a True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 519, size_out = 519 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 855, size_out = 855 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 413, size_out = 413 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 300, size_out = 300 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 152, size_out = 152 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1206, size_out = 1206 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_com_sun_management_OperatingSystem_initialize@8, address_out = 0x6da42a5b True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = _Java_com_sun_management_OperatingSystem_getTotalPhysicalMemorySize@8, address_out = 0x6da4230d True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7192, size_out = 7192 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 536, size_out = 536 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 22580, size_out = 22580 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 325, size_out = 325 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2388, size_out = 2388 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1746, size_out = 1746 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 845, size_out = 845 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 14934, size_out = 14934 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 322, size_out = 322 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1032, size_out = 1032 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 773, size_out = 773 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 122, size_out = 122 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.080316539076114361006181509658991106.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.080316539076114361006181509658991106.class, type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_createDirectory@12, address_out = 0x720ea812 True 1
Fn
File Create Directory C:\Users\2XC7u663GxWc\fUTkALeaTxM True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\ID.txt, type = file_attributes False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3759, size_out = 3759 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 348, size_out = 348 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\ID.txt, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\DdWDtpinxpf, type = file_attributes False 2
Fn
File Create Directory C:\Users\2XC7u663GxWc\fUTkALeaTxM\DdWDtpinxpf True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\DdWDtpinxpf, type = file_attributes True 3
Fn
Thread 0x44c
15 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:07 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:10 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:13 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:17 (UTC) True 2
Fn
Thread 0x7fc
294 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 26461, size_out = 26461 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4540, size_out = 4540 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1995, size_out = 1995 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1261, size_out = 1261 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4115, size_out = 4115 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_initIDs@8, address_out = 0x71fa6667 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2598, size_out = 2598 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 11029, size_out = 11029 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 296, size_out = 296 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1028, size_out = 1028 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 17440, size_out = 17440 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3033, size_out = 3033 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 861, size_out = 861 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2660, size_out = 2660 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1444, size_out = 1444 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1192, size_out = 1192 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 7071, size_out = 7071 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2038, size_out = 2038 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2049, size_out = 2049 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1627, size_out = 1627 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8760, size_out = 8760 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3164, size_out = 3164 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2552, size_out = 2552 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1600, size_out = 1600 True 1
Fn
Data
File Read size = 109, size_out = 109 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 235, size_out = 235 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2863, size_out = 2863 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 443, size_out = 443 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 837, size_out = 837 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3196, size_out = 3196 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = time True 1
Fn
File Read size = 1262, size_out = 1262 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 2
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 160, size_out = 160 True 2
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 590, size_out = 590 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 525, size_out = 525 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1320, size_out = 1320 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1812, size_out = 1812 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 240, size_out = 240 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1434, size_out = 1434 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2863, size_out = 2863 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 390, size_out = 390 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 242, size_out = 242 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1989, size_out = 1989 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 837, size_out = 837 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 734, size_out = 734 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 235, size_out = 235 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5122, size_out = 5122 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 285, size_out = 285 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 889, size_out = 889 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3271, size_out = 3271 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 496, size_out = 496 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1812, size_out = 1812 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 302, size_out = 302 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 23927, size_out = 23927 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1227, size_out = 1227 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 761, size_out = 761 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 107, size_out = 107 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2146, size_out = 2146 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 975, size_out = 975 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 2114, size_out = 2114 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3293, size_out = 3293 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 634, size_out = 634 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 725, size_out = 725 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 859, size_out = 859 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 745, size_out = 745 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1326, size_out = 1326 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 4319, size_out = 4319 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 595, size_out = 595 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 626, size_out = 626 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 763, size_out = 763 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 2191, size_out = 2191 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 913, size_out = 913 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 852, size_out = 852 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1269, size_out = 1269 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 404, size_out = 404 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, base_address = 0x6b6c0000 True 1
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = Unknown module name, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1399, size_out = 1399 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3618, size_out = 3618 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1507, size_out = 1507 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 8099, size_out = 8099 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 964, size_out = 964 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 1312, size_out = 1312 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 5799, size_out = 5799 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_socket0@16, address_out = 0x71fa66ab True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 686, size_out = 686 True 1
Fn
Data
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:04 (UTC) True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = size, size_out = 3070 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 3605, size_out = 3605 True 1
Fn
Data
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 331, size_out = 331 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_connect0@20, address_out = 0x71fa6793 True 1
Fn
File Read size = 160, size_out = 160 True 1
Fn
Data
File Read size = 30, size_out = 30 True 1
Fn
Data
File Read size = 278, size_out = 278 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x71fa99e3 True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_gc@8, address_out = 0x720e2caf True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:05 (UTC) True 1
Fn
Thread 0x930
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:08 (UTC) True 1
Fn
Thread 0x934
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:11 (UTC) True 1
Fn
Thread 0x938
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:14 (UTC) True 1
Fn
Thread 0x940
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:18 (UTC) True 1
Fn
Thread 0xa00
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Thread 0x9e8
3 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:50:18 (UTC) True 1
Fn
Thread 0x9f0
8 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_shutdown@8, address_out = 0x6ce50ac0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SendMessageW, address_out = 0x76b55539 True 1
Fn
System Sleep duration = 100 milliseconds (0.100 seconds) True 1
Fn
Process #21: cmd.exe
58 0
»
Information Value
ID #21
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:01, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0x110
Parent PID 0xf58 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 814
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
private_0x0000000000050000 0x00050000 0x0014ffff Private Memory - True - False -
private_0x0000000000150000 0x00150000 0x0024ffff Private Memory - True - False -
locale.nls 0x00250000 0x002b6fff Memory Mapped File - False - False -
pagefile_0x00000000002c0000 0x002c0000 0x002c6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000002d0000 0x002d0000 0x002d1fff Pagefile Backed Memory - True - False -
private_0x00000000002e0000 0x002e0000 0x002e0fff Private Memory - True - False -
private_0x00000000002f0000 0x002f0000 0x002f0fff Private Memory - True - False -
cscript.exe 0x00300000 0x00321fff Memory Mapped File - False - False -
private_0x0000000000330000 0x00330000 0x0033ffff Private Memory - True - False -
pagefile_0x0000000000340000 0x00340000 0x00407fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000410000 0x00410000 0x00510fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000520000 0x00520000 0x0111ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001120000 0x01120000 0x013aafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x013b0000 0x0167efff Memory Mapped File - False - False -
cscript.exe.mui 0x01680000 0x01682fff Memory Mapped File - False - False -
cmd.exe 0x49e70000 0x49ebbfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x814
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:01 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10912472 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x49e70000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7U6~1\AppData\Local\Temp True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x114, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #22: cscript.exe
93 0
»
Information Value
ID #22
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:02, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0x114
Parent PID 0x110 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 788
0x 118
0x 4D4
0x 134
0x 498
0x 85C
0x 170
0x 264
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
private_0x00000000000d0000 0x000d0000 0x000dffff Private Memory - True - False -
cscript.exe.mui 0x000e0000 0x000e2fff Memory Mapped File - False - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
private_0x0000000000100000 0x00100000 0x00100fff Private Memory - True - False -
cscript.exe 0x00110000 0x0011bfff Memory Mapped File - True - False -
cscript.exe 0x00120000 0x00141fff Memory Mapped File - True - False -
pagefile_0x0000000000150000 0x00150000 0x00217fff Pagefile Backed Memory - True - False -
private_0x0000000000220000 0x00220000 0x0031ffff Private Memory - True - False -
pagefile_0x0000000000320000 0x00320000 0x00420fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000430000 0x00430000 0x00430fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000440000 0x00440000 0x00440fff Pagefile Backed Memory - True - False -
retrive5186310507301951599.vbs 0x00450000 0x00450fff Memory Mapped File - True - False -
private_0x0000000000450000 0x00450000 0x0045ffff Private Memory - True - False -
retrive5186310507301951599.vbs 0x00460000 0x00460fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00460000 0x0046efff Memory Mapped File - False - False -
private_0x0000000000470000 0x00470000 0x0056ffff Private Memory - True - False -
pagefile_0x0000000000570000 0x00570000 0x0116ffff Pagefile Backed Memory - True - False -
rpcss.dll 0x01170000 0x011cbfff Memory Mapped File - False - False -
private_0x0000000001170000 0x01170000 0x0128ffff Private Memory - True - False -
pagefile_0x0000000001170000 0x01170000 0x0124efff Pagefile Backed Memory - True - False -
private_0x0000000001250000 0x01250000 0x0128ffff Private Memory - True - False -
rsaenh.dll 0x01290000 0x012cbfff Memory Mapped File - False - False -
private_0x0000000001290000 0x01290000 0x0130ffff Private Memory - True - False -
private_0x0000000001360000 0x01360000 0x0145ffff Private Memory - True - False -
sortdefault.nls 0x01460000 0x0172efff Memory Mapped File - False - False -
private_0x0000000001740000 0x01740000 0x0183ffff Private Memory - True - False -
private_0x00000000018e0000 0x018e0000 0x019dffff Private Memory - True - False -
pagefile_0x00000000019e0000 0x019e0000 0x01ddffff Pagefile Backed Memory - True - False -
private_0x0000000001de0000 0x01de0000 0x01edffff Private Memory - True - False -
private_0x0000000001ee0000 0x01ee0000 0x01f8ffff Private Memory - True - False -
private_0x0000000001fa0000 0x01fa0000 0x0209ffff Private Memory - True - False -
private_0x00000000020a0000 0x020a0000 0x021bffff Private Memory - True - False -
private_0x0000000002280000 0x02280000 0x0237ffff Private Memory - True - False -
private_0x0000000002570000 0x02570000 0x0266ffff Private Memory - True - False -
private_0x00000000026f0000 0x026f0000 0x027effff Private Memory - True - False -
wbemdisp.dll 0x6cc00000 0x6cc30fff Memory Mapped File - True - False -
scrobj.dll 0x6cc40000 0x6cc6cfff Memory Mapped File - True - False -
comctl32.dll 0x6cc70000 0x6ccf3fff Memory Mapped File - False - False -
wshext.dll 0x6cd30000 0x6cd45fff Memory Mapped File - True - False -
vbscript.dll 0x6cd50000 0x6cdbafff Memory Mapped File - True - False -
msisip.dll 0x6da40000 0x6da47fff Memory Mapped File - False - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x788
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:02 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10912659 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0x120000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 244, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 244, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 244, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10912925 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive5186310507301951599.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x4d4
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 860976 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 860976 False 1
Fn
Process #23: cmd.exe
58 0
»
Information Value
ID #23
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:03, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x400
Parent PID 0xfb8 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 3B8
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory - True - False -
private_0x00000000000d0000 0x000d0000 0x001cffff Private Memory - True - False -
pagefile_0x00000000001d0000 0x001d0000 0x001d1fff Pagefile Backed Memory - True - False -
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory - True - False -
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory - True - False -
private_0x0000000000200000 0x00200000 0x002fffff Private Memory - True - False -
pagefile_0x0000000000300000 0x00300000 0x003c7fff Pagefile Backed Memory - True - False -
cscript.exe 0x003d0000 0x003f1fff Memory Mapped File - False - False -
cscript.exe.mui 0x00400000 0x00402fff Memory Mapped File - False - False -
private_0x0000000000460000 0x00460000 0x0046ffff Private Memory - True - False -
pagefile_0x0000000000470000 0x00470000 0x00570fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000580000 0x00580000 0x0117ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001180000 0x01180000 0x0140afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01410000 0x016defff Memory Mapped File - False - False -
cmd.exe 0x49e70000 0x49ebbfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x3b8
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10913673 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x49e70000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7U6~1\AppData\Local\Temp True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x130, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #24: cscript.exe
93 0
»
Information Value
ID #24
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:03, Reason: Child Process
Unmonitor End Time: 00:01:04, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x130
Parent PID 0x400 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 310
0x 710
0x 88C
0x 878
0x 8EC
0x 4BC
0x 8FC
0x 660
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
cscript.exe 0x00100000 0x0010bfff Memory Mapped File - True - False -
pagefile_0x0000000000110000 0x00110000 0x00110fff Pagefile Backed Memory - True - False -
cscript.exe 0x00120000 0x00141fff Memory Mapped File - True - False -
pagefile_0x0000000000150000 0x00150000 0x00217fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000220000 0x00220000 0x00220fff Pagefile Backed Memory - True - False -
retrive466295784543991919.vbs 0x00230000 0x00230fff Memory Mapped File - True - False -
private_0x0000000000230000 0x00230000 0x0023ffff Private Memory - True - False -
retrive466295784543991919.vbs 0x00240000 0x00240fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00240000 0x0024efff Memory Mapped File - False - False -
private_0x0000000000260000 0x00260000 0x0026ffff Private Memory - True - False -
private_0x0000000000270000 0x00270000 0x0036ffff Private Memory - True - False -
rpcss.dll 0x00370000 0x003cbfff Memory Mapped File - False - False -
pagefile_0x0000000000370000 0x00370000 0x0044efff Pagefile Backed Memory - True - False -
private_0x0000000000470000 0x00470000 0x0056ffff Private Memory - True - False -
pagefile_0x0000000000570000 0x00570000 0x00670fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000680000 0x00680000 0x0127ffff Pagefile Backed Memory - True - False -
private_0x0000000001280000 0x01280000 0x013cffff Private Memory - True - False -
rsaenh.dll 0x01280000 0x012bbfff Memory Mapped File - False - False -
private_0x0000000001280000 0x01280000 0x012effff Private Memory - True - False -
private_0x00000000012f0000 0x012f0000 0x0137ffff Private Memory - True - False -
private_0x0000000001390000 0x01390000 0x013cffff Private Memory - True - False -
private_0x00000000013d0000 0x013d0000 0x014cffff Private Memory - True - False -
private_0x0000000001510000 0x01510000 0x0160ffff Private Memory - True - False -
sortdefault.nls 0x01610000 0x018defff Memory Mapped File - False - False -
private_0x0000000001900000 0x01900000 0x019fffff Private Memory - True - False -
private_0x0000000001b10000 0x01b10000 0x01c0ffff Private Memory - True - False -
pagefile_0x0000000001c10000 0x01c10000 0x0200ffff Pagefile Backed Memory - True - False -
private_0x0000000002040000 0x02040000 0x0213ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0227ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0223ffff Private Memory - True - False -
private_0x0000000002240000 0x02240000 0x0227ffff Private Memory - True - False -
private_0x0000000002310000 0x02310000 0x0240ffff Private Memory - True - False -
private_0x0000000002520000 0x02520000 0x0261ffff Private Memory - True - False -
wbemdisp.dll 0x6cc00000 0x6cc30fff Memory Mapped File - True - False -
scrobj.dll 0x6cc40000 0x6cc6cfff Memory Mapped File - True - False -
comctl32.dll 0x6cc70000 0x6ccf3fff Memory Mapped File - False - False -
wshext.dll 0x6cd30000 0x6cd45fff Memory Mapped File - True - False -
vbscript.dll 0x6cd50000 0x6cdbafff Memory Mapped File - True - False -
msisip.dll 0x6da40000 0x6da47fff Memory Mapped File - False - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x310
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10913736 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0x120000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 216, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 216, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10913783 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive466295784543991919.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x88c
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 2499376 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 2499376 False 1
Fn
Process #25: cmd.exe
58 0
»
Information Value
ID #25
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:03, Reason: Child Process
Unmonitor End Time: 00:01:06, Reason: Self Terminated
Monitor Duration 00:00:03
OS Process Information
»
Information Value
PID 0x754
Parent PID 0xf58 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 624
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
private_0x0000000000030000 0x00030000 0x0012ffff Private Memory - True - False -
pagefile_0x0000000000130000 0x00130000 0x00133fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000140000 0x00140000 0x00140fff Pagefile Backed Memory - True - False -
locale.nls 0x00150000 0x001b6fff Memory Mapped File - False - False -
pagefile_0x00000000001c0000 0x001c0000 0x00287fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000290000 0x00290000 0x00296fff Pagefile Backed Memory - True - False -
pagefile_0x00000000002a0000 0x002a0000 0x002a1fff Pagefile Backed Memory - True - False -
private_0x00000000002b0000 0x002b0000 0x002b0fff Private Memory - True - False -
private_0x00000000002c0000 0x002c0000 0x002c0fff Private Memory - True - False -
cscript.exe 0x002d0000 0x002f1fff Memory Mapped File - False - False -
cscript.exe.mui 0x00300000 0x00302fff Memory Mapped File - False - False -
private_0x0000000000310000 0x00310000 0x0040ffff Private Memory - True - False -
pagefile_0x0000000000410000 0x00410000 0x00510fff Pagefile Backed Memory - True - False -
private_0x00000000005d0000 0x005d0000 0x005dffff Private Memory - True - False -
pagefile_0x00000000005e0000 0x005e0000 0x011dffff Pagefile Backed Memory - True - False -
pagefile_0x00000000011e0000 0x011e0000 0x0146afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01470000 0x0173efff Memory Mapped File - False - False -
cmd.exe 0x49e70000 0x49ebbfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x624
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10914126 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x49e70000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7U6~1\AppData\Local\Temp True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x904, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #26: cmd.exe
58 0
»
Information Value
ID #26
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:03, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0x588
Parent PID 0xfb8 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 154
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory - True - False -
private_0x0000000000070000 0x00070000 0x0016ffff Private Memory - True - False -
locale.nls 0x00170000 0x001d6fff Memory Mapped File - False - False -
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory - True - False -
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory - True - False -
cscript.exe 0x00200000 0x00221fff Memory Mapped File - False - False -
private_0x0000000000230000 0x00230000 0x0032ffff Private Memory - True - False -
cscript.exe.mui 0x00330000 0x00332fff Memory Mapped File - False - False -
private_0x0000000000390000 0x00390000 0x0039ffff Private Memory - True - False -
pagefile_0x00000000003a0000 0x003a0000 0x00467fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000470000 0x00470000 0x00570fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000580000 0x00580000 0x0117ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001180000 0x01180000 0x0140afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01410000 0x016defff Memory Mapped File - False - False -
cmd.exe 0x49e70000 0x49ebbfff Memory Mapped File - True - False -
winbrand.dll 0x6e390000 0x6e396fff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x154
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10914173 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x49e70000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp, type = file_attributes True 2
Fn
Environment Set Environment String name = =C:, value = C:\Users\2XC7U6~1\AppData\Local\Temp True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x7557ac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x75583ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x75592732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes False 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x924, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #27: cscript.exe
92 0
»
Information Value
ID #27
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:04, Reason: Child Process
Unmonitor End Time: 00:01:05, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x924
Parent PID 0x588 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 948
0x 958
0x 960
0x 96C
0x 214
0x 1CC
0x 460
0x 174
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000effff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
private_0x0000000000100000 0x00100000 0x00100fff Private Memory - True - False -
rpcss.dll 0x00110000 0x0016bfff Memory Mapped File - False - False -
cscript.exe 0x00110000 0x0011bfff Memory Mapped File - True - False -
pagefile_0x0000000000120000 0x00120000 0x00120fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000130000 0x00130000 0x00130fff Pagefile Backed Memory - True - False -
retrive3068316261550961408.vbs 0x00140000 0x00140fff Memory Mapped File - True - False -
rsaenh.dll 0x00140000 0x0017bfff Memory Mapped File - False - False -
private_0x0000000000140000 0x00140000 0x0014ffff Private Memory - True - False -
retrive3068316261550961408.vbs 0x00150000 0x00150fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00150000 0x0015efff Memory Mapped File - False - False -
private_0x0000000000180000 0x00180000 0x0027ffff Private Memory - True - False -
private_0x0000000000280000 0x00280000 0x002cffff Private Memory - True - False -
private_0x0000000000320000 0x00320000 0x0041ffff Private Memory - True - False -
pagefile_0x0000000000420000 0x00420000 0x004e7fff Pagefile Backed Memory - True - False -
pagefile_0x00000000004f0000 0x004f0000 0x005f0fff Pagefile Backed Memory - True - False -
private_0x0000000000600000 0x00600000 0x0075ffff Private Memory - True - False -
pagefile_0x0000000000600000 0x00600000 0x006defff Pagefile Backed Memory - True - False -
private_0x0000000000720000 0x00720000 0x0075ffff Private Memory - True - False -
private_0x0000000000780000 0x00780000 0x0087ffff Private Memory - True - False -
private_0x0000000000890000 0x00890000 0x0098ffff Private Memory - True - False -
private_0x00000000009e0000 0x009e0000 0x00adffff Private Memory - True - False -
private_0x0000000000ae0000 0x00ae0000 0x00b3ffff Private Memory - True - False -
cscript.exe 0x00b80000 0x00ba1fff Memory Mapped File - True - False -
pagefile_0x0000000000bb0000 0x00bb0000 0x017affff Pagefile Backed Memory - True - False -
sortdefault.nls 0x017b0000 0x01a7efff Memory Mapped File - False - False -
pagefile_0x0000000001a80000 0x01a80000 0x01e7ffff Pagefile Backed Memory - True - False -
private_0x0000000001f40000 0x01f40000 0x0203ffff Private Memory - True - False -
private_0x0000000002040000 0x02040000 0x0213ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x022effff Private Memory - True - False -
private_0x0000000002150000 0x02150000 0x0224ffff Private Memory - True - False -
private_0x00000000022b0000 0x022b0000 0x022effff Private Memory - True - False -
private_0x0000000002330000 0x02330000 0x0242ffff Private Memory - True - False -
private_0x0000000002500000 0x02500000 0x025fffff Private Memory - True - False -
comctl32.dll 0x6cc00000 0x6cc83fff Memory Mapped File - False - False -
vbscript.dll 0x6cc90000 0x6ccfafff Memory Mapped File - True - False -
wbemdisp.dll 0x6cd30000 0x6cd60fff Memory Mapped File - True - False -
scrobj.dll 0x6cd70000 0x6cd9cfff Memory Mapped File - True - False -
wshext.dll 0x6cda0000 0x6cdb5fff Memory Mapped File - True - False -
msisip.dll 0x6da30000 0x6da37fff Memory Mapped File - False - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x948
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10914297 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xb80000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 132, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 132, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 132, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 124, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 124, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 208, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 208, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10914407 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3068316261550961408.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x960
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 926512 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 926512 False 1
Fn
Process #28: cscript.exe
92 0
»
Information Value
ID #28
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs
Initial Working Directory C:\Users\2XC7U6~1\AppData\Local\Temp\
Monitor Start Time: 00:01:04, Reason: Child Process
Unmonitor End Time: 00:01:06, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0x904
Parent PID 0x754 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 908
0x 94C
0x 95C
0x 7F4
0x 5FC
0x 8AC
0x 158
0x 970
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
rpcss.dll 0x00100000 0x0015bfff Memory Mapped File - False - False -
cscript.exe 0x00100000 0x0010bfff Memory Mapped File - True - False -
pagefile_0x0000000000110000 0x00110000 0x00110fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000120000 0x00120000 0x00120fff Pagefile Backed Memory - True - False -
retrive1625750400979200631.vbs 0x00130000 0x00130fff Memory Mapped File - True - False -
private_0x0000000000130000 0x00130000 0x0013ffff Private Memory - True - False -
retrive1625750400979200631.vbs 0x00140000 0x00140fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00140000 0x0014efff Memory Mapped File - False - False -
private_0x0000000000160000 0x00160000 0x0025ffff Private Memory - True - False -
pagefile_0x0000000000260000 0x00260000 0x00327fff Pagefile Backed Memory - True - False -
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory - True - False -
rsaenh.dll 0x00360000 0x0039bfff Memory Mapped File - False - False -
private_0x0000000000360000 0x00360000 0x003cffff Private Memory - True - False -
private_0x00000000003f0000 0x003f0000 0x004effff Private Memory - True - False -
pagefile_0x00000000004f0000 0x004f0000 0x005f0fff Pagefile Backed Memory - True - False -
private_0x0000000000600000 0x00600000 0x0069ffff Private Memory - True - False -
pagefile_0x00000000006a0000 0x006a0000 0x0077efff Pagefile Backed Memory - True - False -
private_0x00000000007c0000 0x007c0000 0x008bffff Private Memory - True - False -
private_0x00000000008f0000 0x008f0000 0x009effff Private Memory - True - False -
private_0x0000000000a10000 0x00a10000 0x00b0ffff Private Memory - True - False -
cscript.exe 0x00b80000 0x00ba1fff Memory Mapped File - True - False -
pagefile_0x0000000000bb0000 0x00bb0000 0x017affff Pagefile Backed Memory - True - False -
sortdefault.nls 0x017b0000 0x01a7efff Memory Mapped File - False - False -
pagefile_0x0000000001a80000 0x01a80000 0x01e7ffff Pagefile Backed Memory - True - False -
private_0x0000000001e80000 0x01e80000 0x01faffff Private Memory - True - False -
private_0x0000000001e80000 0x01e80000 0x01f7ffff Private Memory - True - False -
private_0x0000000001fa0000 0x01fa0000 0x01faffff Private Memory - True - False -
private_0x0000000001fe0000 0x01fe0000 0x020dffff Private Memory - True - False -
private_0x00000000020e0000 0x020e0000 0x0225ffff Private Memory - True - False -
private_0x0000000002310000 0x02310000 0x0240ffff Private Memory - True - False -
private_0x0000000002440000 0x02440000 0x0253ffff Private Memory - True - False -
private_0x0000000002620000 0x02620000 0x0271ffff Private Memory - True - False -
comctl32.dll 0x6cc00000 0x6cc83fff Memory Mapped File - False - False -
vbscript.dll 0x6cc90000 0x6ccfafff Memory Mapped File - True - False -
wbemdisp.dll 0x6cd30000 0x6cd60fff Memory Mapped File - True - False -
scrobj.dll 0x6cd70000 0x6cd9cfff Memory Mapped File - True - False -
wshext.dll 0x6cda0000 0x6cdb5fff Memory Mapped File - True - False -
msisip.dll 0x6da30000 0x6da37fff Memory Mapped File - False - False -
wmiutils.dll 0x70770000 0x70786fff Memory Mapped File - False - False -
wbemsvc.dll 0x70970000 0x7097efff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x71280000 0x712dbfff Memory Mapped File - False - False -
dwmapi.dll 0x731f0000 0x73202fff Memory Mapped File - False - False -
uxtheme.dll 0x73530000 0x7356ffff Memory Mapped File - False - False -
version.dll 0x74450000 0x74458fff Memory Mapped File - False - False -
rsaenh.dll 0x74770000 0x747aafff Memory Mapped File - False - False -
cryptsp.dll 0x749d0000 0x749e5fff Memory Mapped File - False - False -
cryptbase.dll 0x74e50000 0x74e5bfff Memory Mapped File - False - False -
sxs.dll 0x74e60000 0x74ebefff Memory Mapped File - False - False -
rpcrtremote.dll 0x74ef0000 0x74efdfff Memory Mapped File - False - False -
msasn1.dll 0x74f70000 0x74f7bfff Memory Mapped File - False - False -
crypt32.dll 0x74f80000 0x7509cfff Memory Mapped File - False - False -
wintrust.dll 0x750c0000 0x750ecfff Memory Mapped File - False - False -
kernelbase.dll 0x75180000 0x751c9fff Memory Mapped File - False - False -
imm32.dll 0x75200000 0x7521efff Memory Mapped File - False - False -
shlwapi.dll 0x75220000 0x75276fff Memory Mapped File - False - False -
advapi32.dll 0x75280000 0x7531ffff Memory Mapped File - False - False -
msctf.dll 0x75370000 0x7543bfff Memory Mapped File - False - False -
sechost.dll 0x75440000 0x75458fff Memory Mapped File - False - False -
clbcatq.dll 0x75460000 0x754e2fff Memory Mapped File - False - False -
gdi32.dll 0x754f0000 0x7553dfff Memory Mapped File - False - False -
kernel32.dll 0x75540000 0x75613fff Memory Mapped File - False - False -
msvcrt.dll 0x75650000 0x756fbfff Memory Mapped File - False - False -
shell32.dll 0x75700000 0x76349fff Memory Mapped File - False - False -
ole32.dll 0x76360000 0x764bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x764c0000 0x76560fff Memory Mapped File - False - False -
usp10.dll 0x76570000 0x7660cfff Memory Mapped File - False - False -
nsi.dll 0x76850000 0x76855fff Memory Mapped File - False - False -
ws2_32.dll 0x76870000 0x768a4fff Memory Mapped File - False - False -
oleaut32.dll 0x76ab0000 0x76b3efff Memory Mapped File - False - False -
user32.dll 0x76b40000 0x76c08fff Memory Mapped File - False - False -
ntdll.dll 0x76db0000 0x76eebfff Memory Mapped File - False - False -
lpk.dll 0x76f50000 0x76f59fff Memory Mapped File - False - False -
apisetschema.dll 0x76ff0000 0x76ff0fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x908
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 2018-07-19 09:50:03 (UTC) True 1
Fn
System Get Time type = Ticks, time = 10914251 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xb80000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755924c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 84, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 84, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 84, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x75540000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x75594157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 103, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 103, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 160, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 160, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x76360000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x763a9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 10914344 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x752a2102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x752a3352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x752a3825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1625750400979200631.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x763a6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x7636cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75280000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x7528ca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x7636c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x95c
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 3482416 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 3482416 False 1
Fn
Process #30: javaw.exe
5574 21
»
Information Value
ID #30
File Name c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe
Command Line "C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe" -jar "C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm"
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:01:48, Reason: Autostart
Unmonitor End Time: 00:05:11, Reason: Terminated by Timeout
Monitor Duration 00:03:23
OS Process Information
»
Information Value
PID 0x35c
Parent PID 0x7f4 (c:\windows\explorer.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 378
0x 158
0x 3A0
0x 4DC
0x 4E0
0x 4D4
0x 4C4
0x 4CC
0x 4C0
0x 4BC
0x 5E4
0x 344
0x 318
0x 314
0x 57C
0x 134
0x 4D8
0x 6B0
0x 76C
0x 15C
0x 74C
0x 46C
0x 558
0x 250
0x 4B4
0x 21C
0x 318
0x 340
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
private_0x0000000000020000 0x00020000 0x00020fff Private Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00042fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
private_0x00000000000c0000 0x000c0000 0x000c0fff Private Memory - True - False -
tzres.dll 0x000d0000 0x000d0fff Memory Mapped File - False - False -
pagefile_0x00000000000d0000 0x000d0000 0x000d0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000e0000 0x000e0000 0x000e1fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000f0000 0x000f0000 0x000f6fff Pagefile Backed Memory - True - False -
private_0x0000000000100000 0x00100000 0x0014ffff Private Memory - True - False -
pagefile_0x0000000000150000 0x00150000 0x00217fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000220000 0x00220000 0x00221fff Pagefile Backed Memory - True - False -
private_0x0000000000230000 0x00230000 0x00230fff Private Memory - True - False -
private_0x0000000000240000 0x00240000 0x00240fff Private Memory - True - False -
860 0x00250000 0x0025ffff Memory Mapped File - True - False -
private_0x0000000000260000 0x00260000 0x0028ffff Private Memory - True - False -
javaw.exe 0x00290000 0x002befff Memory Mapped File - True - False -
pagefile_0x00000000002c0000 0x002c0000 0x003c0fff Pagefile Backed Memory - True - False -
private_0x00000000003d0000 0x003d0000 0x0042ffff Private Memory - True - False -
private_0x0000000000430000 0x00430000 0x0043ffff Private Memory - True - False -
private_0x0000000000440000 0x00440000 0x0044ffff Private Memory - True - False -
private_0x0000000000450000 0x00450000 0x0045ffff Private Memory - True - False -
private_0x0000000000460000 0x00460000 0x0046ffff Private Memory - True - False -
rsaenh.dll 0x00470000 0x004abfff Memory Mapped File - False - False -
private_0x00000000004b0000 0x004b0000 0x005affff Private Memory - True - False -
pagefile_0x00000000005b0000 0x005b0000 0x011affff Pagefile Backed Memory - True - False -
private_0x00000000011b0000 0x011b0000 0x012affff Private Memory - True - False -
private_0x00000000011b0000 0x011b0000 0x0125ffff Private Memory - True - False -
private_0x00000000011d0000 0x011d0000 0x0121ffff Private Memory - True - False -
private_0x0000000001250000 0x01250000 0x0125ffff Private Memory - True - False -
private_0x00000000012a0000 0x012a0000 0x012affff Private Memory - True - False -
private_0x00000000012b0000 0x012b0000 0x013affff Private Memory - True - False -
pagefile_0x00000000013b0000 0x013b0000 0x017a2fff Pagefile Backed Memory - True - False -
private_0x00000000017b0000 0x017b0000 0x0189ffff Private Memory - True - False -
private_0x00000000017b0000 0x017b0000 0x0182ffff Private Memory - True - False -
private_0x0000000001860000 0x01860000 0x0189ffff Private Memory - True - False -
private_0x00000000018a0000 0x018a0000 0x0199ffff Private Memory - True - False -
private_0x00000000019a0000 0x019a0000 0x0399ffff Private Memory - True - False -
private_0x00000000039a0000 0x039a0000 0x03a4ffff Private Memory - True - False -
private_0x0000000003a90000 0x03a90000 0x03adffff Private Memory - True - False -
private_0x0000000003b10000 0x03b10000 0x03b5ffff Private Memory - True - False -
private_0x0000000003b80000 0x03b80000 0x03bcffff Private Memory - True - False -
private_0x0000000003c70000 0x03c70000 0x03cbffff Private Memory - True - False -
private_0x0000000003ce0000 0x03ce0000 0x03d2ffff Private Memory - True - False -
private_0x0000000003d70000 0x03d70000 0x03dbffff Private Memory - True - False -
private_0x0000000003e70000 0x03e70000 0x03ebffff Private Memory - True - False -
private_0x0000000003f50000 0x03f50000 0x03f9ffff Private Memory - True - False -
private_0x0000000003fa0000 0x03fa0000 0x0419ffff Private Memory - True - False -
sortdefault.nls 0x041a0000 0x0446efff Memory Mapped File - False - False -
private_0x0000000004470000 0x04470000 0x0456ffff Private Memory - True - False -
kernelbase.dll.mui 0x04470000 0x0452ffff Memory Mapped File - False - False -
private_0x0000000004530000 0x04530000 0x0456ffff Private Memory - True - False -
private_0x0000000004570000 0x04570000 0x0468ffff Private Memory - True - False -
private_0x00000000045a0000 0x045a0000 0x045effff Private Memory - True - False -
private_0x0000000004680000 0x04680000 0x0468ffff Private Memory - True - False -
private_0x0000000004690000 0x04690000 0x0476ffff Private Memory - True - False -
private_0x0000000004770000 0x04770000 0x048fffff Private Memory - True - False -
private_0x0000000004770000 0x04770000 0x0486ffff Private Memory - True - False -
private_0x00000000048c0000 0x048c0000 0x048fffff Private Memory - True - False -
private_0x0000000004900000 0x04900000 0x04cfffff Private Memory - True - False -
private_0x0000000004d00000 0x04d00000 0x054fffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x394cffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x394cffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x394cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x394cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x380cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x37b0ffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - True - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x394cffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x38ccffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x3871ffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - True - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x394cffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x390cffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x38f3ffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - True - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x394cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
awt.dll 0x6fae0000 0x6fc22fff Memory Mapped File - True - False -
net.dll 0x6fe40000 0x6fe53fff Memory Mapped File - True - False -
sunec.dll 0x6fe60000 0x6fe7ffff Memory Mapped File - True - False -
zip.dll 0x6fe80000 0x6fe92fff Memory Mapped File - True - False -
java.dll 0x6fea0000 0x6febffff Memory Mapped File - True - False -
msvcr100.dll 0x700e0000 0x7019efff Memory Mapped File - True - False -
winrnr.dll 0x702b0000 0x702b7fff Memory Mapped File - False - False -
pnrpnsp.dll 0x702c0000 0x702d1fff Memory Mapped File - False - False -
napinsp.dll 0x702e0000 0x702effff Memory Mapped File - False - False -
winmm.dll 0x704a0000 0x704d1fff Memory Mapped File - False - False -
rasadhlp.dll 0x719f0000 0x719f5fff Memory Mapped File - False - False -
nio.dll 0x71c10000 0x71c1efff Memory Mapped File - True - False -
verify.dll 0x71c20000 0x71c2bfff Memory Mapped File - True - False -
jvm.dll 0x72880000 0x72bfffff Memory Mapped File - True - False -
fwpuclnt.dll 0x73260000 0x73297fff Memory Mapped File - False - False -
winnsi.dll 0x73370000 0x73376fff Memory Mapped File - False - False -
iphlpapi.dll 0x73380000 0x7339bfff Memory Mapped File - False - False -
nlaapi.dll 0x734e0000 0x734effff Memory Mapped File - False - False -
wsock32.dll 0x73a30000 0x73a36fff Memory Mapped File - False - False -
comctl32.dll 0x74110000 0x742adfff Memory Mapped File - False - False -
wshtcpip.dll 0x74710000 0x74714fff Memory Mapped File - False - False -
userenv.dll 0x747e0000 0x747f6fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
dnsapi.dll 0x74a80000 0x74ac3fff Memory Mapped File - False - False -
wship6.dll 0x74bb0000 0x74bb5fff Memory Mapped File - False - False -
mswsock.dll 0x74bc0000 0x74bfbfff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
profapi.dll 0x75130000 0x7513afff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
psapi.dll 0x754e0000 0x754e4fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 33 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860 64.00 KB MD5: fcd6bcb56c1689fcef28b57c22475bad
SHA1: 1adc95bebe9eea8c112d40cd04ab7a8d75c4f961
SHA256: de2f256064a0af797747c2b97505dc0b9f3df0de4f489eac731c23ae9ca9cc31
SSDeep: 3::
False
Threads
Thread 0x378
42 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:00 (UTC) True 1
Fn
System Get Time type = Ticks, time = 23462 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x755f418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x755f1e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755f76e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x755f1f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 22, size_out = 22 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 1024, size_out = 1024 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 686 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 0 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\msvcr100.dll, type = file_attributes True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\msvcr100.dll, base_address = 0x700e0000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x755f418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x755f1e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755f76e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x755f1f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
Environment Get Environment String - True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:02 (UTC) True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_CreateJavaVM, address_out = 0x72948e70 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_GetDefaultJavaVMInitArgs, address_out = 0x7293e340 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x158
4654 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Environment Get Environment String name = _ALT_JAVA_HOME_DIR False 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, size = 260 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\verify.dll, base_address = 0x71c20000 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.dll, base_address = 0x6fea0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, address_out = 0x6fea6fcf True 1
Fn
Environment Get Environment String name = JAVA_TOOL_OPTIONS False 1
Fn
Environment Get Environment String name = _JAVA_OPTIONS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\endorsed, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 2
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
File Create Directory C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_DELETE_ON_CLOSE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860, protection = PAGE_READWRITE, maximum_size = 65536 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_ALL_ACCESS True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, base_address = 0x6fe80000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_Open, address_out = 0x6fe83af6 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_Close, address_out = 0x6fe83a1c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_FindEntry, address_out = 0x6fe83661 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_ReadEntry, address_out = 0x6fe83697 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_ReadMappedEntry, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_GetNextEntry, address_out = 0x6fe83622 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = Canonicalize, address_out = 0x6fea5f09 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 4096, size_out = 2190 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 4096, size_out = 0 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, size = 2416, size_out = 2416 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, size = 65536, size_out = 65536 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Object_registerNatives@8, address_out = 0x6fea20dc True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_registerNatives@8, address_out = 0x6fea3035 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_identityHashCode@12, address_out = 0x6fea3050 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Thread_registerNatives@8, address_out = 0x6fea467c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_getStackAccessControlContext@8, address_out = 0x6fea1064 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_getInheritedAccessControlContext@8, address_out = 0x6fea1069 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_registerNatives@8, address_out = 0x6fea1498 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedAction_2@12, address_out = 0x6fea1000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_registerNatives@8, address_out = 0x6fea12da True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_getPrimitiveClass@12, address_out = 0x6fea1445 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Float_floatToRawIntBits@12, address_out = 0x6fea20cc True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Double_doubleToRawLongBits@16, address_out = 0x6fea1ce8 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_VM_initialize@8, address_out = 0x6fea87ac True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JVM_GetVersionInfo, address_out = 0x7296d980 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_initProperties@12, address_out = 0x6fea3350 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x755dbe77 True 1
Fn
System Get Info type = Hardware Information True 2
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = NewStringPlatform, address_out = 0x6fea6cc9 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_maxMemory@8, address_out = 0x6fea2ca7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Throwable_fillInStackTrace@12, address_out = 0x6fea4697 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_Reflection_getCallerClass@8, address_out = 0x6fea7d85 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_String_intern@8, address_out = 0x6fea12d5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_initIDs@8, address_out = 0x6fea1dd1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileDescriptor_initIDs@8, address_out = 0x6fea1d29 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1781193, size_out = 1781193 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 709, size_out = 709 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 277, size_out = 277 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileDescriptor_set@12, address_out = 0x6fea1d6a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileOutputStream_initIDs@8, address_out = 0x6fea1fbf True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2305, size_out = 2305 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_freeMemory@8, address_out = 0x6fea2c97 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setIn0@12, address_out = 0x6fea44d1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Object_getClass@8, address_out = 0x6fea20f7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_forName0@20, address_out = 0x6fea1300 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1022, size_out = 1022 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_Reflection_getClassAccessFlags@12, address_out = 0x6fea7da3 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_NativeConstructorAccessorImpl_newInstance0@16, address_out = 0x6fea7d71 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2882, size_out = 2882 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 104, size_out = 104 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 728, size_out = 728 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 345, size_out = 345 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setOut0@12, address_out = 0x6fea4507 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setErr0@12, address_out = 0x6fea453d True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileSystem_getFileSystem@8, address_out = 0x6fea1cfb True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_Win32FileSystem_initIDs@8, address_out = 0x6fea8f36 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_initIDs@8, address_out = 0x6fea9b30 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetFinalPathNameByHandleW, address_out = 0x755d4e2a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_mapLibraryName@12, address_out = 0x6fea4594 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 815, size_out = 815 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_getBooleanAttributes@12, address_out = 0x6feaa1a8 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_canonicalize0@12, address_out = 0x6fea9e1d True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_00024NativeLibrary_load@12, address_out = 0x6fea18e4 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, base_address = 0x6fe80000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_Signal_findSignal@12, address_out = 0x6fea46b5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_Signal_handle0@20, address_out = 0x6fea46ef True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_io_Win32ErrorMode_setErrorMode@16, address_out = 0x6feac3d5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Compiler_registerNatives@8, address_out = 0x6fea1b79 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_isAssignableFrom@12, address_out = 0x6fea141b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1105, size_out = 1105 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1761, size_out = 1761 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_concurrent_atomic_AtomicLong_VMSupportsCS8@8, address_out = 0x6fea83ed True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 514, size_out = 514 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 970, size_out = 970 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2589, size_out = 2589 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1008, size_out = 1008 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_00024NativeLibrary_find@12, address_out = 0x6fea1ae7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedExceptionAction_2@12, address_out = 0x6fea1032 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_attributes True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_open@12, address_out = 0x6fea1df4 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2004, size_out = 2004 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 669, size_out = 669 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_readBytes@20, address_out = 0x6fea1e2c True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, size = 8192, size_out = 829 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_available@8, address_out = 0x6fea1f10 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = size, size_out = 829 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_reflect_Array_newArray@16, address_out = 0x6fea12ad True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 962, size_out = 962 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 934, size_out = 934 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1720, size_out = 1720 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1012, size_out = 1012 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_availableProcessors@8, address_out = 0x6fea2d11 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3028, size_out = 3028 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2976, size_out = 2976 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 672, size_out = 672 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1189, size_out = 1189 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2646, size_out = 2646 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, size = 8192, size_out = 0 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_close0@8, address_out = 0x6fea1fa6 True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_list@12, address_out = 0x6feaa570 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 966, size_out = 966 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 800, size_out = 800 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_canonicalizeWithPrefix0@16, address_out = 0x6fea9f47 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1280, size_out = 1280 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 609, size_out = 609 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 628, size_out = 628 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 327, size_out = 327 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 4
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\management\usagetracker.properties, type = file_attributes False 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JVM_FindClassFromBootLoader, address_out = 0x72975a90 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 12212, size_out = 12212 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_initIDs@8, address_out = 0x6fe8190b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 748, size_out = 748 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6630, size_out = 6630 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3392, size_out = 3392 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_getLastModifiedTime@12, address_out = 0x6feaa314 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = time True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_open@28, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_open@28, address_out = 0x6fe81960 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30105, size_out = 30105 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 476, size_out = 476 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2703, size_out = 2703 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 753, size_out = 753 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3690, size_out = 3690 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3361, size_out = 3361 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getTotal@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getTotal@16, address_out = 0x6fe81a47 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_startsWithLOC@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_startsWithLOC@16, address_out = 0x6fe81a51 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3599, size_out = 3599 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntry@24, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntry@24, address_out = 0x6fe81a67 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryFlag@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryFlag@16, address_out = 0x6fe81b65 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryTime@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryTime@16, address_out = 0x6fe81b97 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryCrc@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryCrc@16, address_out = 0x6fe81ba3 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntrySize@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntrySize@16, address_out = 0x6fe81b8a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryCSize@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryCSize@16, address_out = 0x6fe81b6f True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryMethod@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryMethod@16, address_out = 0x6fe81b4f True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryBytes@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryBytes@20, address_out = 0x6fe81bed True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_freeEntry@24, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_freeEntry@24, address_out = 0x6fe81b2c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_initIDs@8, address_out = 0x6fe81583 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 260, size_out = 260 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_init@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_init@12, address_out = 0x6fe8160b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1899, size_out = 1899 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 678, size_out = 678 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_inflateBytes@28, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_inflateBytes@28, address_out = 0x6fe816f2 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_read@44, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_read@44, address_out = 0x6fe81cba True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_reset@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_reset@16, address_out = 0x6fe818c5 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1909, size_out = 1909 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 670, size_out = 670 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_end@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_end@16, address_out = 0x6fe818e1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_close@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_close@16, address_out = 0x6fe81a5b True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_findLoadedClass0@12, address_out = 0x6fea1876 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_findBootstrapClass@12, address_out = 0x6fea17e7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedExceptionAction_2Ljava_security_AccessControlContext_2@16, address_out = 0x6fea104a True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 762, size_out = 762 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30105, size_out = 30105 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Package_getSystemPackage0@12, address_out = 0x6fea269c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_jar_JarFile_getMetaInfEntryNames@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_jar_JarFile_getMetaInfEntryNames@8, address_out = 0x6fe81da5 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 100, size_out = 100 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 391, size_out = 391 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_defineClass1@32, address_out = 0x6fea150c True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 452, size_out = 452 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 536, size_out = 536 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 521, size_out = 521 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 491, size_out = 491 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 506, size_out = 506 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 515, size_out = 515 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 361, size_out = 361 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 675, size_out = 675 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 451, size_out = 451 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 355, size_out = 355 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 299, size_out = 299 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 474, size_out = 474 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 655, size_out = 655 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 303, size_out = 303 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 335, size_out = 335 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 418, size_out = 418 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 430, size_out = 430 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 453, size_out = 453 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 555, size_out = 555 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 408, size_out = 408 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 477, size_out = 477 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 562, size_out = 562 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 394, size_out = 394 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 477, size_out = 477 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 462, size_out = 462 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 371, size_out = 371 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 231, size_out = 231 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 691, size_out = 691 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 509, size_out = 509 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 580, size_out = 580 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 391, size_out = 391 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 348, size_out = 348 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 802, size_out = 802 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1127, size_out = 1127 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = size, size_out = 2190 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\meta-index, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:05 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedAction_2Ljava_security_AccessControlContext_2@16, address_out = 0x6fea1018 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 329, size_out = 329 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 383, size_out = 383 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 332, size_out = 332 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 348, size_out = 348 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 461, size_out = 461 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 570, size_out = 570 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 5504, size_out = 5504 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 582, size_out = 582 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 535, size_out = 535 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 678, size_out = 678 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 315, size_out = 315 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 6708, size_out = 6708 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 4096, size_out = 4096 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 1693, size_out = 1693 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 1351, size_out = 1351 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 8192 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 1440 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = size, size_out = 17824 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2345, size_out = 2345 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 13694, size_out = 13694 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1056, size_out = 1056 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Double_longBitsToDouble@16, address_out = 0x6fea1cd0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3940, size_out = 3940 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5672, size_out = 5672 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 844, size_out = 844 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1453, size_out = 1453 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 803, size_out = 803 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2601, size_out = 2601 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1240, size_out = 1240 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2666, size_out = 2666 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 314, size_out = 314 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 951, size_out = 951 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 10594, size_out = 10594 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3882, size_out = 3882 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3549, size_out = 3549 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1381, size_out = 1381 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8211, size_out = 8211 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1075, size_out = 1075 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3695, size_out = 3695 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2117, size_out = 2117 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 346, size_out = 346 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 576, size_out = 576 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 24203, size_out = 24203 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 13092, size_out = 13092 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 623, size_out = 623 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3174, size_out = 3174 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2257, size_out = 2257 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1621, size_out = 1621 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2395, size_out = 2395 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 14258, size_out = 14258 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 853, size_out = 853 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 967, size_out = 967 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3914, size_out = 3914 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5828, size_out = 5828 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 12814, size_out = 12814 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4077, size_out = 4077 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2399, size_out = 2399 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2181, size_out = 2181 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 308, size_out = 308 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 381, size_out = 381 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4556, size_out = 4556 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6732, size_out = 6732 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 732, size_out = 732 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 457, size_out = 457 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 973, size_out = 973 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 310, size_out = 310 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2812, size_out = 2812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 131, size_out = 131 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3431, size_out = 3431 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 281, size_out = 281 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5929, size_out = 5929 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6713, size_out = 6713 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 265, size_out = 265 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6705, size_out = 6705 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3395, size_out = 3395 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1337, size_out = 1337 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5120, size_out = 5120 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 374, size_out = 374 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1663, size_out = 1663 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4945, size_out = 4945 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2801, size_out = 2801 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2263, size_out = 2263 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4843, size_out = 4843 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2266, size_out = 2266 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3589, size_out = 3589 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2498, size_out = 2498 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2363, size_out = 2363 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 631, size_out = 631 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 866, size_out = 866 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 282, size_out = 282 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3850, size_out = 3850 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 591, size_out = 591 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 907, size_out = 907 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3908, size_out = 3908 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8490, size_out = 8490 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 444, size_out = 444 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4645, size_out = 4645 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 11624, size_out = 11624 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 915, size_out = 915 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:06 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 390, size_out = 390 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunec.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:06 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunec.dll, base_address = 0x6fe60000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 5439, size_out = 5439 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 619, size_out = 619 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 10470, size_out = 10470 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 735, size_out = 735 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:06 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4170, size_out = 4170 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 817, size_out = 817 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2357, size_out = 2357 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 187, size_out = 187 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3665, size_out = 3665 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 3856, size_out = 3856 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 333, size_out = 333 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\local_policy.jar, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 2915, size_out = 2915 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
For performance reasons, the remaining 3472 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x3a0
128 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:06 (UTC) True 5
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:07 (UTC) True 5
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 5
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 5
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:10 (UTC) True 3
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:38 (UTC) True 44
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:24 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:47 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:03 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:11 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:57 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:59 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:00 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:20 (UTC) True 9
Fn
Thread 0x4dc
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x4e0
81 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ref_Finalizer_invokeFinalizeMethod@12, address_out = 0x6fea207c True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:38 (UTC) True 41
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ProcessImpl_closeHandle@16, address_out = 0x6fea8e8b True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:24 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:47 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:11 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:57 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:20 (UTC) True 7
Fn
Thread 0x4d4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x4c4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x4cc
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Mutex Create - True 1
Fn
Thread 0x4c0
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x4bc
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
Thread 0x344
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x318
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x314
35 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x6fb72210 True 1
Fn
Module Load module_name = COMCTL32.dll, base_address = 0x74110000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x741309ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x7588f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x7588ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x7589544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75ec0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x75ec6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x75895421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x7588ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x7589507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x7588e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6fb71da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x75caefd7 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 569, size_out = 569 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 333, size_out = 333 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_eventLoop@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_eventLoop@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_eventLoop@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_eventLoop@8, address_out = 0x6fb71290 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = WaitMessage, address_out = 0x758966bd True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x7589634a True 1
Fn
Thread 0x57c
268 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 706, size_out = 706 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\zoIZCxYZMIr.EAMkwm, size = 3, size_out = 3 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 448, size_out = 448 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4013, size_out = 4013 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1566, size_out = 1566 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 402, size_out = 402 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1366, size_out = 1366 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 9311, size_out = 9311 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3572, size_out = 3572 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1619, size_out = 1619 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2404, size_out = 2404 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3013, size_out = 3013 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1708, size_out = 1708 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2879, size_out = 2879 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1285, size_out = 1285 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1398, size_out = 1398 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1090, size_out = 1090 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3789, size_out = 3789 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 436, size_out = 436 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 792, size_out = 792 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 384, size_out = 384 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1217, size_out = 1217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 480, size_out = 480 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 622, size_out = 622 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 76, size_out = 76 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 527, size_out = 527 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4051, size_out = 4051 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7991, size_out = 7991 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 704, size_out = 704 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8401, size_out = 8401 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2096, size_out = 2096 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2691, size_out = 2691 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, os_pid = 0x558, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, size = 281 True 1
Fn
Data
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, os_pid = 0x42c, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, size = 8192, size_out = 108 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1396, size_out = 1396 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 582, size_out = 582 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 46400, size_out = 46400 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 263, size_out = 263 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 357, size_out = 357 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5472, size_out = 5472 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3241, size_out = 3241 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 784, size_out = 784 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1886, size_out = 1886 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5529, size_out = 5529 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:10 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:10 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1188, size_out = 1188 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 213, size_out = 213 True 1
Fn
Data
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetFriendlyIfIndex, address_out = 0x7338d855 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIpAddrTable, address_out = 0x73389bb0 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetAdaptersAddresses, address_out = 0x73386a4d True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 878, size_out = 878 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7520, size_out = 7520 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8446, size_out = 8446 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:10 (UTC) True 2
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x738e2194 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5830, size_out = 5830 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1929, size_out = 1929 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 519, size_out = 519 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 855, size_out = 855 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 413, size_out = 413 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 300, size_out = 300 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 152, size_out = 152 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1206, size_out = 1206 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7192, size_out = 7192 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 536, size_out = 536 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 22580, size_out = 22580 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 325, size_out = 325 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2388, size_out = 2388 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1746, size_out = 1746 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 845, size_out = 845 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 14934, size_out = 14934 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 322, size_out = 322 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1032, size_out = 1032 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 773, size_out = 773 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 122, size_out = 122 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\ID.txt, type = file_attributes True 1
Fn
File Read size = 8192, size_out = 47 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 47 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\cqsFQOTqbmg\nccJQMiokAP, type = file_attributes True 4
Fn
Thread 0x134
27 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 2
Fn
System Sleep duration = 2000 milliseconds (2.000 seconds) True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:40 (UTC) True 2
Fn
System Sleep duration = 2000 milliseconds (2.000 seconds) True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:03 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:26 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:50 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:13 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:36 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:59 (UTC) True 2
Fn
Thread 0x4d8
282 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 26461, size_out = 26461 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4540, size_out = 4540 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1995, size_out = 1995 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1261, size_out = 1261 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4115, size_out = 4115 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2598, size_out = 2598 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 11029, size_out = 11029 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 296, size_out = 296 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1028, size_out = 1028 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 17440, size_out = 17440 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3033, size_out = 3033 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 861, size_out = 861 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2660, size_out = 2660 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1444, size_out = 1444 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1192, size_out = 1192 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7071, size_out = 7071 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2038, size_out = 2038 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2049, size_out = 2049 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1627, size_out = 1627 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 8760, size_out = 8760 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3164, size_out = 3164 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2552, size_out = 2552 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1600, size_out = 1600 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 109, size_out = 109 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 235, size_out = 235 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 2863, size_out = 2863 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 443, size_out = 443 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 837, size_out = 837 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 3196, size_out = 3196 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1262, size_out = 1262 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1812, size_out = 1812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 240, size_out = 240 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 2863, size_out = 2863 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 390, size_out = 390 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1989, size_out = 1989 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 837, size_out = 837 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 734, size_out = 734 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 235, size_out = 235 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5122, size_out = 5122 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 285, size_out = 285 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 889, size_out = 889 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3271, size_out = 3271 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1812, size_out = 1812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 302, size_out = 302 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 23927, size_out = 23927 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1227, size_out = 1227 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 761, size_out = 761 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 107, size_out = 107 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2146, size_out = 2146 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 975, size_out = 975 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2114, size_out = 2114 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3293, size_out = 3293 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 634, size_out = 634 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 725, size_out = 725 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 859, size_out = 859 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 745, size_out = 745 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1326, size_out = 1326 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4319, size_out = 4319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 595, size_out = 595 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 626, size_out = 626 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 763, size_out = 763 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 2191, size_out = 2191 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 913, size_out = 913 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 852, size_out = 852 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1269, size_out = 1269 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 404, size_out = 404 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1399, size_out = 1399 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3618, size_out = 3618 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1507, size_out = 1507 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 8099, size_out = 8099 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 964, size_out = 964 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1312, size_out = 1312 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 5799, size_out = 5799 True 1
Fn
Data
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 686, size_out = 686 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read size = 8192, size_out = 3070 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 3070 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3605, size_out = 3605 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_java_net_DualStackPlainSocketImpl_close0@12, address_out = 0x6fe499e3 True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_gc@8, address_out = 0x6fea2caf True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:38 (UTC) True 1
Fn
Thread 0x6b0
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 1
Fn
Thread 0x76c
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x15c
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x74c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:24 (UTC) True 1
Fn
Thread 0x46c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:47 (UTC) True 1
Fn
Thread 0x558
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x250
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:11 (UTC) True 1
Fn
Thread 0x4b4
3 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:03 (UTC) True 2
Fn
Thread 0x21c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 1
Fn
Thread 0x318
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:57 (UTC) True 1
Fn
Thread 0x340
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:20 (UTC) True 1
Fn
Process #31: java.exe
3856 125
»
Information Value
ID #31
File Name c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe
Command Line C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe -jar C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:01, Reason: Child Process
Unmonitor End Time: 00:05:11, Reason: Terminated by Timeout
Monitor Duration 00:03:10
OS Process Information
»
Information Value
PID 0x290
Parent PID 0x35c (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 268
0x 2B0
0x 350
0x 338
0x 334
0x 660
0x 348
0x 628
0x 32C
0x 4A4
0x 330
0x 79C
0x 5B0
0x 78C
0x 6AC
0x 6E4
0x 74C
0x 274
0x 768
0x 564
0x 784
0x 46C
0x 57C
0x 774
0x 188
0x 318
0x 230
0x 5D8
0x 30C
0x 574
0x 624
0x 718
0x 7A0
0x 274
0x 7AC
0x 7A8
0x 768
0x 64
0x 564
0x 154
0x 784
0x 57C
0x 174
0x 7A4
0x 6AC
0x 180
0x 718
0x 500
0x 228
0x 6D8
0x 2D8
0x 218
0x 64
0x 728
0x 340
0x 638
0x 790
0x 6AC
0x 180
0x 658
0x 718
0x 66C
0x 46C
0x 76C
0x 228
0x 6D8
0x 244
0x 210
0x 260
0x 64
0x 70C
0x 71C
0x 4B4
0x B0
0x 124
0x 638
0x 778
0x 740
0x 690
0x 768
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
private_0x0000000000040000 0x00040000 0x0008ffff Private Memory - True - False -
pagefile_0x0000000000090000 0x00090000 0x00092fff Pagefile Backed Memory - True - False -
locale.nls 0x000a0000 0x00106fff Memory Mapped File - False - False -
private_0x0000000000110000 0x00110000 0x00110fff Private Memory - True - False -
private_0x0000000000120000 0x00120000 0x00120fff Private Memory - True - False -
tzres.dll 0x00130000 0x00130fff Memory Mapped File - False - False -
pagefile_0x0000000000130000 0x00130000 0x00130fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000140000 0x00140000 0x00141fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000150000 0x00150000 0x00156fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000160000 0x00160000 0x00161fff Pagefile Backed Memory - True - False -
private_0x0000000000170000 0x00170000 0x00170fff Private Memory - True - False -
private_0x0000000000180000 0x00180000 0x0027ffff Private Memory - True - False -
pagefile_0x0000000000280000 0x00280000 0x00347fff Pagefile Backed Memory - True - False -
private_0x0000000000350000 0x00350000 0x00350fff Private Memory - True - False -
656 0x00360000 0x0036ffff Memory Mapped File rw True True False
private_0x0000000000370000 0x00370000 0x0039ffff Private Memory - True - False -
private_0x00000000003a0000 0x003a0000 0x003affff Private Memory - True - False -
private_0x00000000003b0000 0x003b0000 0x003bffff Private Memory - True - False -
private_0x00000000003c0000 0x003c0000 0x003cffff Private Memory - True - False -
pagefile_0x00000000003d0000 0x003d0000 0x004d0fff Pagefile Backed Memory - True - False -
private_0x00000000004e0000 0x004e0000 0x005bffff Private Memory - True - False -
private_0x00000000004e0000 0x004e0000 0x0055ffff Private Memory - True - False -
private_0x0000000000560000 0x00560000 0x0059ffff Private Memory - True - False -
private_0x00000000005b0000 0x005b0000 0x005bffff Private Memory - True - False -
private_0x00000000005c0000 0x005c0000 0x006bffff Private Memory - True - False -
pagefile_0x00000000006c0000 0x006c0000 0x00ab2fff Pagefile Backed Memory - True - False -
java.exe 0x00af0000 0x00b1efff Memory Mapped File - True - False -
pagefile_0x0000000000b20000 0x00b20000 0x0171ffff Pagefile Backed Memory - True - False -
private_0x0000000001720000 0x01720000 0x0190ffff Private Memory - True - False -
private_0x0000000001740000 0x01740000 0x0178ffff Private Memory - True - False -
private_0x0000000001790000 0x01790000 0x0188ffff Private Memory - True - False -
private_0x0000000001890000 0x01890000 0x018effff Private Memory - True - False -
private_0x0000000001900000 0x01900000 0x0190ffff Private Memory - True - False -
private_0x0000000001910000 0x01910000 0x01b1ffff Private Memory - True - False -
private_0x0000000001910000 0x01910000 0x019bffff Private Memory - True - False -
private_0x00000000019c0000 0x019c0000 0x019fffff Private Memory - True - False -
rsaenh.dll 0x01a00000 0x01a3bfff Memory Mapped File - False - False -
private_0x0000000001a50000 0x01a50000 0x01a9ffff Private Memory - True - False -
private_0x0000000001ae0000 0x01ae0000 0x01b1ffff Private Memory - True - False -
private_0x0000000001b20000 0x01b20000 0x03b1ffff Private Memory - True - False -
private_0x0000000003b60000 0x03b60000 0x03baffff Private Memory - True - False -
private_0x0000000003bb0000 0x03bb0000 0x03bfffff Private Memory - True - False -
private_0x0000000003c90000 0x03c90000 0x03cdffff Private Memory - True - False -
private_0x0000000003d30000 0x03d30000 0x03d7ffff Private Memory - True - False -
private_0x0000000003dd0000 0x03dd0000 0x03e1ffff Private Memory - True - False -
private_0x0000000003e90000 0x03e90000 0x03edffff Private Memory - True - False -
private_0x0000000003f00000 0x03f00000 0x03f4ffff Private Memory - True - False -
private_0x0000000003f80000 0x03f80000 0x03fcffff Private Memory - True - False -
private_0x0000000003fd0000 0x03fd0000 0x041cffff Private Memory - True - False -
sortdefault.nls 0x041d0000 0x0449efff Memory Mapped File - False - False -
private_0x00000000044a0000 0x044a0000 0x0469ffff Private Memory - True - False -
private_0x00000000044a0000 0x044a0000 0x045cffff Private Memory - True - False -
private_0x00000000044a0000 0x044a0000 0x0459ffff Private Memory - True - False -
private_0x00000000045c0000 0x045c0000 0x045cffff Private Memory - True - False -
private_0x0000000004660000 0x04660000 0x0469ffff Private Memory - True - False -
private_0x00000000046a0000 0x046a0000 0x0483ffff Private Memory - True - False -
kernelbase.dll.mui 0x046a0000 0x0475ffff Memory Mapped File - False - False -
private_0x0000000004780000 0x04780000 0x047cffff Private Memory - True - False -
private_0x0000000004800000 0x04800000 0x0483ffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x394cffff Private Memory - True - False -
private_0x00000000236d0000 0x236d0000 0x28c1ffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x394cffff Private Memory - True - False -
private_0x0000000028c20000 0x28c20000 0x336cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x394cffff Private Memory - True - False -
private_0x00000000336d0000 0x336d0000 0x376cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x394cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x380cffff Private Memory - True - False -
private_0x00000000376d0000 0x376d0000 0x37b0ffff Private Memory - True - False -
classes.jsa 0x376d0000 0x37b0ffff Memory Mapped File - True - False -
private_0x0000000037b10000 0x37b10000 0x380cffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x394cffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x38ccffff Private Memory - True - False -
private_0x00000000380d0000 0x380d0000 0x3871ffff Private Memory - True - False -
classes.jsa 0x380d0000 0x3871ffff Memory Mapped File - True - False -
private_0x0000000038720000 0x38720000 0x38ccffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x394cffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x390cffff Private Memory - True - False -
private_0x0000000038cd0000 0x38cd0000 0x38f3ffff Private Memory - True - False -
classes.jsa 0x38cd0000 0x38f3ffff Memory Mapped File - True - False -
private_0x0000000038f40000 0x38f40000 0x390cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x394cffff Private Memory - True - False -
private_0x00000000390d0000 0x390d0000 0x390dffff Private Memory - True - False -
private_0x00000000390e0000 0x390e0000 0x394cffff Private Memory - True - False -
awt.dll 0x6fae0000 0x6fc22fff Memory Mapped File - True - False -
net.dll 0x6fe40000 0x6fe53fff Memory Mapped File - True - False -
sunec.dll 0x6fe60000 0x6fe7ffff Memory Mapped File - True - False -
zip.dll 0x6fe80000 0x6fe92fff Memory Mapped File - True - False -
java.dll 0x6fea0000 0x6febffff Memory Mapped File - True - False -
msvcr100.dll 0x700e0000 0x7019efff Memory Mapped File - True - False -
winrnr.dll 0x702b0000 0x702b7fff Memory Mapped File - False - False -
pnrpnsp.dll 0x702c0000 0x702d1fff Memory Mapped File - False - False -
napinsp.dll 0x702e0000 0x702effff Memory Mapped File - False - False -
winmm.dll 0x704a0000 0x704d1fff Memory Mapped File - False - False -
rasadhlp.dll 0x719f0000 0x719f5fff Memory Mapped File - False - False -
nio.dll 0x71c10000 0x71c1efff Memory Mapped File - True - False -
verify.dll 0x71c20000 0x71c2bfff Memory Mapped File - True - False -
jvm.dll 0x72880000 0x72bfffff Memory Mapped File - True - False -
fwpuclnt.dll 0x73260000 0x73297fff Memory Mapped File - False - False -
winnsi.dll 0x73370000 0x73376fff Memory Mapped File - False - False -
iphlpapi.dll 0x73380000 0x7339bfff Memory Mapped File - False - False -
nlaapi.dll 0x734e0000 0x734effff Memory Mapped File - False - False -
wsock32.dll 0x73a30000 0x73a36fff Memory Mapped File - False - False -
comctl32.dll 0x74110000 0x742adfff Memory Mapped File - False - False -
wshtcpip.dll 0x74710000 0x74714fff Memory Mapped File - False - False -
userenv.dll 0x747e0000 0x747f6fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
dnsapi.dll 0x74a80000 0x74ac3fff Memory Mapped File - False - False -
wship6.dll 0x74bb0000 0x74bb5fff Memory Mapped File - False - False -
mswsock.dll 0x74bc0000 0x74bfbfff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
profapi.dll 0x75130000 0x7513afff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
psapi.dll 0x754e0000 0x754e4fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd4000 0x7ffd4000 0x7ffd4fff Private Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd6000 0x7ffd6000 0x7ffd6fff Private Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
For performance reasons, the remaining 62 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
»
Filename File Size Hash Values YARA Match Actions
C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive4432003530389164433.vbs 0.27 KB MD5: a32c109297ed1ca155598cd295c26611
SHA1: dc4a1fdbaad15ddd6fe22d3907c6b03727b71510
SHA256: 45bfe34aa3ef932f75101246eb53d032f5e7cf6d1f5b4e495334955a255f32e7
SSDeep: 6:jpxiFtqvAAT+geD5NaqZxLMTQQQavbx3la2Zp6djsyn:vmtqvAndZFcQU9lrXyjsyn
False
C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\860 64.00 KB MD5: fcd6bcb56c1689fcef28b57c22475bad
SHA1: 1adc95bebe9eea8c112d40cd04ab7a8d75c4f961
SHA256: de2f256064a0af797747c2b97505dc0b9f3df0de4f489eac731c23ae9ca9cc31
SSDeep: 3::
False
Threads
Thread 0x268
47 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:07 (UTC) True 1
Fn
System Get Time type = Ticks, time = 30295 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x755f418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x755f1e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755f76e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x755f1f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 22, size_out = 22 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 1024, size_out = 1024 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 161, size_out = 161 True 1
Fn
Data
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 686 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\i386\jvm.cfg, size = 4096, size_out = 0 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\msvcr100.dll, base_address = 0x700e0000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsAlloc, address_out = 0x755f418d True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsGetValue, address_out = 0x755f1e16 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsSetValue, address_out = 0x755f76e6 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = FlsFree, address_out = 0x755f1f61 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info filename = STD_INPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Get Info filename = STD_OUTPUT_HANDLE, type = file_type True 1
Fn
File Open filename = STD_ERROR_HANDLE True 1
Fn
File Get Info filename = STD_ERROR_HANDLE, type = file_type True 1
Fn
Environment Get Environment String - True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:07 (UTC) True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_CreateJavaVM, address_out = 0x72948e70 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JNI_GetDefaultJavaVMInitArgs, address_out = 0x7293e340 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x2b0
2497 5
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
System Get Info type = Operating System True 1
Fn
Environment Get Environment String name = _ALT_JAVA_HOME_DIR False 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Filename process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.exe, size = 260 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\verify.dll, base_address = 0x71c20000 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\java.dll, base_address = 0x6fea0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, address_out = 0x6fea6fcf True 1
Fn
Environment Get Environment String name = JAVA_TOOL_OPTIONS False 1
Fn
Environment Get Environment String name = _JAVA_OPTIONS False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\endorsed, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:07 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 2
Fn
Process Open desired_access = PROCESS_QUERY_INFORMATION True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
Module Get Handle module_name = c:\windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SetSecurityDescriptorControl, address_out = 0x75e17a8b True 1
Fn
File Create Directory C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\656, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_FLAG_DELETE_ON_CLOSE, share_mode = FILE_SHARE_READ, FILE_SHARE_DELETE True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\656, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\656, protection = PAGE_READWRITE, maximum_size = 65536 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\\hsperfdata_2XC7u663GxWc\656, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, desired_access = FILE_MAP_ALL_ACCESS True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, base_address = 0x6fe80000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_Open, address_out = 0x6fe83af6 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_Close, address_out = 0x6fe83a1c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_FindEntry, address_out = 0x6fe83661 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_ReadEntry, address_out = 0x6fe83697 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_ReadMappedEntry, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = ZIP_GetNextEntry, address_out = 0x6fe83622 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = Canonicalize, address_out = 0x6fea5f09 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_type True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, type = file_type True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, size = 2416, size_out = 2416 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, desired_access = FILE_MAP_READ True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, protection = PAGE_WRITECOPY, maximum_size = 0 True 1
Fn
Module Map C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, desired_access = FILE_MAP_COPY True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\classes.jsa, size = 65536, size_out = 65536 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Object_registerNatives@8, address_out = 0x6fea20dc True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_registerNatives@8, address_out = 0x6fea3035 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_identityHashCode@12, address_out = 0x6fea3050 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Thread_registerNatives@8, address_out = 0x6fea467c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_getStackAccessControlContext@8, address_out = 0x6fea1064 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_getInheritedAccessControlContext@8, address_out = 0x6fea1069 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_registerNatives@8, address_out = 0x6fea1498 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedAction_2@12, address_out = 0x6fea1000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 2
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_registerNatives@8, address_out = 0x6fea12da True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_getPrimitiveClass@12, address_out = 0x6fea1445 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Float_floatToRawIntBits@12, address_out = 0x6fea20cc True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Double_doubleToRawLongBits@16, address_out = 0x6fea1ce8 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_VM_initialize@8, address_out = 0x6fea87ac True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JVM_GetVersionInfo, address_out = 0x7296d980 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_initProperties@12, address_out = 0x6fea3350 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x755dbe77 True 1
Fn
System Get Info type = Hardware Information True 2
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, value_name = Desktop, data = C:\Users\2XC7u663GxWc\Desktop, type = REG_SZ True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Filename module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, process_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe, file_name_orig = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\client\jvm.dll, size = 260 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = NewStringPlatform, address_out = 0x6fea6cc9 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_maxMemory@8, address_out = 0x6fea2ca7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Throwable_fillInStackTrace@12, address_out = 0x6fea4697 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_Reflection_getCallerClass@8, address_out = 0x6fea7d85 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_String_intern@8, address_out = 0x6fea12d5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_initIDs@8, address_out = 0x6fea1dd1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileDescriptor_initIDs@8, address_out = 0x6fea1d29 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1781193, size_out = 1781193 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 709, size_out = 709 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 277, size_out = 277 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileDescriptor_set@12, address_out = 0x6fea1d6a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileOutputStream_initIDs@8, address_out = 0x6fea1fbf True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2305, size_out = 2305 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_freeMemory@8, address_out = 0x6fea2c97 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setIn0@12, address_out = 0x6fea44d1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Object_getClass@8, address_out = 0x6fea20f7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_forName0@20, address_out = 0x6fea1300 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1022, size_out = 1022 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_Reflection_getClassAccessFlags@12, address_out = 0x6fea7da3 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_NativeConstructorAccessorImpl_newInstance0@16, address_out = 0x6fea7d71 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2882, size_out = 2882 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 104, size_out = 104 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 728, size_out = 728 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 345, size_out = 345 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setOut0@12, address_out = 0x6fea4507 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_setErr0@12, address_out = 0x6fea453d True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileSystem_getFileSystem@8, address_out = 0x6fea1cfb True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_Win32FileSystem_initIDs@8, address_out = 0x6fea8f36 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_initIDs@8, address_out = 0x6fea9b30 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = GetFinalPathNameByHandleW, address_out = 0x755d4e2a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_System_mapLibraryName@12, address_out = 0x6fea4594 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 815, size_out = 815 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_getBooleanAttributes@12, address_out = 0x6feaa1a8 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_canonicalize0@12, address_out = 0x6fea9e1d True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_00024NativeLibrary_load@12, address_out = 0x6fea18e4 True 1
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\zip.dll, base_address = 0x6fe80000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_Signal_findSignal@12, address_out = 0x6fea46b5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_Signal_handle0@20, address_out = 0x6fea46ef True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_io_Win32ErrorMode_setErrorMode@16, address_out = 0x6feac3d5 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Compiler_registerNatives@8, address_out = 0x6fea1b79 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_isAssignableFrom@12, address_out = 0x6fea141b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1105, size_out = 1105 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1761, size_out = 1761 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_concurrent_atomic_AtomicLong_VMSupportsCS8@8, address_out = 0x6fea83ed True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 514, size_out = 514 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 970, size_out = 970 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2589, size_out = 2589 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1008, size_out = 1008 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_00024NativeLibrary_find@12, address_out = 0x6fea1ae7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedExceptionAction_2@12, address_out = 0x6fea1032 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_attributes True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_open@12, address_out = 0x6fea1df4 True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2004, size_out = 2004 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 669, size_out = 669 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_readBytes@20, address_out = 0x6fea1e2c True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, size = 8192, size_out = 829 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_available@8, address_out = 0x6fea1f10 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, type = size, size_out = 829 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_reflect_Array_newArray@16, address_out = 0x6fea12ad True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 962, size_out = 962 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 934, size_out = 934 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1720, size_out = 1720 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1012, size_out = 1012 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Runtime_availableProcessors@8, address_out = 0x6fea2d11 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3028, size_out = 3028 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2976, size_out = 2976 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 672, size_out = 672 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1189, size_out = 1189 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2646, size_out = 2646 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\meta-index, size = 8192, size_out = 0 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_FileInputStream_close0@8, address_out = 0x6fea1fa6 True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext\meta-index, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_list@12, address_out = 0x6feaa570 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 966, size_out = 966 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 800, size_out = 800 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_canonicalizeWithPrefix0@16, address_out = 0x6fea9f47 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\Sun\Java\lib\ext, type = file_attributes False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1280, size_out = 1280 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 609, size_out = 609 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 628, size_out = 628 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 328, size_out = 328 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 327, size_out = 327 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = file_attributes True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 4
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\management\usagetracker.properties, type = file_attributes False 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Handle module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, base_address = 0x72880000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\client\jvm.dll, function = JVM_FindClassFromBootLoader, address_out = 0x72975a90 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 12212, size_out = 12212 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_initIDs@8, address_out = 0x6fe8190b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 748, size_out = 748 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6630, size_out = 6630 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3392, size_out = 3392 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_WinNTFileSystem_getLastModifiedTime@12, address_out = 0x6feaa314 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = time True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_open@28, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_open@28, address_out = 0x6fe81960 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 6113, size_out = 6113 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 476, size_out = 476 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2703, size_out = 2703 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 753, size_out = 753 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3690, size_out = 3690 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3361, size_out = 3361 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getTotal@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getTotal@16, address_out = 0x6fe81a47 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_startsWithLOC@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_startsWithLOC@16, address_out = 0x6fe81a51 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3599, size_out = 3599 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntry@24, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntry@24, address_out = 0x6fe81a67 True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryFlag@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryFlag@16, address_out = 0x6fe81b65 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryTime@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryTime@16, address_out = 0x6fe81b97 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryCrc@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryCrc@16, address_out = 0x6fe81ba3 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntrySize@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntrySize@16, address_out = 0x6fe81b8a True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryCSize@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryCSize@16, address_out = 0x6fe81b6f True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryMethod@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryMethod@16, address_out = 0x6fe81b4f True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getEntryBytes@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getEntryBytes@20, address_out = 0x6fe81bed True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_freeEntry@24, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_freeEntry@24, address_out = 0x6fe81b2c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_initIDs@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_initIDs@8, address_out = 0x6fe81583 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 260, size_out = 260 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_init@12, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_init@12, address_out = 0x6fe8160b True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1899, size_out = 1899 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 678, size_out = 678 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_inflateBytes@28, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_inflateBytes@28, address_out = 0x6fe816f2 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_read@44, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_read@44, address_out = 0x6fe81cba True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 161, size_out = 161 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_reset@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_reset@16, address_out = 0x6fe818c5 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1909, size_out = 1909 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 670, size_out = 670 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_Inflater_end@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_Inflater_end@16, address_out = 0x6fe818e1 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_close@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_close@16, address_out = 0x6fe81a5b True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_findLoadedClass0@12, address_out = 0x6fea1876 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_findBootstrapClass@12, address_out = 0x6fea17e7 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedExceptionAction_2Ljava_security_AccessControlContext_2@16, address_out = 0x6fea104a True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 762, size_out = 762 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\access-bridge.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\dnsns.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\jaccess.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\localedata.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunpkcs11.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\zipfs.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 6113, size_out = 6113 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 161, size_out = 161 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Package_getSystemPackage0@12, address_out = 0x6fea269c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_jar_JarFile_getMetaInfEntryNames@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_jar_JarFile_getMetaInfEntryNames@8, address_out = 0x6fe81da5 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 161, size_out = 161 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 263, size_out = 263 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ClassLoader_defineClass1@32, address_out = 0x6fea150c True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = VerifyClassCodesForMajorVersion, address_out = 0x6fea4724 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 729, size_out = 729 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 243, size_out = 243 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 315, size_out = 315 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 437, size_out = 437 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 439, size_out = 439 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 342, size_out = 342 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 802, size_out = 802 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1127, size_out = 1127 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib, type = file_attributes True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 8192, size_out = 2190 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, type = size, size_out = 2190 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\meta-index, size = 8192, size_out = 0 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\meta-index, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 2
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\resources.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\sunrsasign.jar, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\charsets.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jfr.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\classes, type = file_attributes False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_security_AccessController_doPrivileged@16, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_security_AccessController_doPrivileged__Ljava_security_PrivilegedAction_2Ljava_security_AccessControlContext_2@16, address_out = 0x6fea1018 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 1468, size_out = 1468 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1486, size_out = 1486 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 258, size_out = 258 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_io_ObjectStreamClass_initNative@8, address_out = 0x6fea25ca True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_misc_VM_latestUserDefinedLoader@8, address_out = 0x6fea87a0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2351, size_out = 2351 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 877, size_out = 877 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 645, size_out = 645 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6444, size_out = 6444 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1453, size_out = 1453 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Class_isInstance@12, address_out = 0x6fea13f8 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 513, size_out = 513 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_reflect_NativeMethodAccessorImpl_invoke0@20, address_out = 0x6fea7d59 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4556, size_out = 4556 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 8192 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 1440 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = file_type True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, type = size, size_out = 17824 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\java.security, size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2345, size_out = 2345 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7, size_out = 7 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 13694, size_out = 13694 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1056, size_out = 1056 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_Double_longBitsToDouble@16, address_out = 0x6fea1cd0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3940, size_out = 3940 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5672, size_out = 5672 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 844, size_out = 844 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 803, size_out = 803 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2601, size_out = 2601 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6732, size_out = 6732 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 732, size_out = 732 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 457, size_out = 457 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 973, size_out = 973 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 308, size_out = 308 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 381, size_out = 381 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 310, size_out = 310 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3431, size_out = 3431 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 281, size_out = 281 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 131, size_out = 131 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5929, size_out = 5929 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 405, size_out = 405 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 182, size_out = 182 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 258, size_out = 258 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 3, size_out = 3 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 354, size_out = 354 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 3, size_out = 3 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 645, size_out = 645 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 380, size_out = 380 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 17, size_out = 17 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 512, size_out = 512 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 6708, size_out = 6708 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 4096, size_out = 4096 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 1693, size_out = 1693 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 1351, size_out = 1351 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1358, size_out = 1358 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1240, size_out = 1240 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2666, size_out = 2666 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 314, size_out = 314 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 951, size_out = 951 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 10594, size_out = 10594 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3882, size_out = 3882 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3549, size_out = 3549 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1381, size_out = 1381 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8211, size_out = 8211 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1075, size_out = 1075 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3695, size_out = 3695 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2117, size_out = 2117 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 346, size_out = 346 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 576, size_out = 576 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 24203, size_out = 24203 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 13092, size_out = 13092 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 623, size_out = 623 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3174, size_out = 3174 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2257, size_out = 2257 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1621, size_out = 1621 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2563, size_out = 2563 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2395, size_out = 2395 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 14258, size_out = 14258 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 853, size_out = 853 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 967, size_out = 967 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3914, size_out = 3914 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5828, size_out = 5828 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 12814, size_out = 12814 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4077, size_out = 4077 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2399, size_out = 2399 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2181, size_out = 2181 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2812, size_out = 2812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6713, size_out = 6713 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 265, size_out = 265 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6705, size_out = 6705 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3395, size_out = 3395 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1337, size_out = 1337 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5120, size_out = 5120 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 374, size_out = 374 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1663, size_out = 1663 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4945, size_out = 4945 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2801, size_out = 2801 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2263, size_out = 2263 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4843, size_out = 4843 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2266, size_out = 2266 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3589, size_out = 3589 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3217, size_out = 3217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2498, size_out = 2498 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2363, size_out = 2363 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 631, size_out = 631 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 866, size_out = 866 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 282, size_out = 282 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3850, size_out = 3850 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 591, size_out = 591 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 907, size_out = 907 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3908, size_out = 3908 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8490, size_out = 8490 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 444, size_out = 444 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4645, size_out = 4645 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 11624, size_out = 11624 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 915, size_out = 915 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 687, size_out = 687 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 11725, size_out = 11725 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1715, size_out = 1715 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1952, size_out = 1952 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1957, size_out = 1957 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1960, size_out = 1960 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1966, size_out = 1966 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 441, size_out = 441 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 723, size_out = 723 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3045, size_out = 3045 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2242, size_out = 2242 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 387, size_out = 387 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6064, size_out = 6064 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1369, size_out = 1369 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4032, size_out = 4032 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunec.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 2
Fn
Module Load module_name = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunec.dll, base_address = 0x6fe60000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = _JNI_OnLoad@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\sunec.dll, function = JNI_OnLoad, address_out = 0x0 False 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 454, size_out = 454 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 5439, size_out = 5439 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 619, size_out = 619 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 10470, size_out = 10470 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3596, size_out = 3596 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3529, size_out = 3529 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 735, size_out = 735 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:08 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4170, size_out = 4170 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 817, size_out = 817 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2357, size_out = 2357 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 187, size_out = 187 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunjce_provider.jar, size = 3665, size_out = 3665 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 3856, size_out = 3856 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 333, size_out = 333 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\local_policy.jar, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 2915, size_out = 2915 True 1
Fn
Data
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, type = time True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 328, size_out = 328 True 1
Fn
Data
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_util_zip_ZipFile_getNextEntry@20, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_java_util_zip_ZipFile_getNextEntry@20, address_out = 0x6fe81b3e True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 350, size_out = 350 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 3
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 213, size_out = 213 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\security\US_export_policy.jar, size = 1319, size_out = 1319 True 1
Fn
Data
For performance reasons, the remaining 1385 entries are omitted.
The remaining entries can be found in glog.xml.
Thread 0x350
257 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 3
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:10 (UTC) True 3
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:11 (UTC) True 3
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:27 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:31 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:34 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:37 (UTC) True 9
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:40 (UTC) True 10
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:43 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:46 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:49 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:52 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:55 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:58 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:05 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:08 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:11 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:13 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:14 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:16 (UTC) True 4
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:17 (UTC) True 8
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:19 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:20 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:23 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:26 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:29 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:32 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:36 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:39 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:42 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:45 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:48 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:51 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:54 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:57 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:00 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:03 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:04 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:07 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:10 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:13 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:16 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:19 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:22 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:25 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:28 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:31 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:37 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:38 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:41 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:43 (UTC) True 4
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:44 (UTC) True 6
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:47 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:50 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:53 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:56 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:59 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:02 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:05 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:08 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:09 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:12 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:15 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:18 (UTC) True 3
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:21 (UTC) True 3
Fn
Thread 0x338
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x334
126 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_java_lang_ref_Finalizer_invokeFinalizeMethod@12, address_out = 0x6fea207c True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:14 (UTC) True 40
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:17 (UTC) True 4
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:20 (UTC) True 4
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:27 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:31 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:34 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:37 (UTC) True 7
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:40 (UTC) True 5
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:43 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:46 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:49 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:52 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:55 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:58 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:05 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:08 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:11 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:14 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:17 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:20 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:23 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:26 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:29 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:32 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:36 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:39 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:42 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:45 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:48 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:51 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:54 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:57 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:00 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:04 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:07 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:10 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:13 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:16 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:19 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:22 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:25 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:28 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:31 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:38 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:41 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:44 (UTC) True 2
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:47 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:50 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:53 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:56 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:59 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:02 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:05 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:09 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:12 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:15 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:18 (UTC) True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:21 (UTC) True 1
Fn
Thread 0x660
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x348
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x628
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Mutex Create - True 1
Fn
Thread 0x32c
2 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
Thread 0x4a4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x79c
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x5b0
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x78c
30 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\zip.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\net.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\nio.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x0 False 1
Fn
Module Get Address module_name = c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\awt.dll, function = _Java_sun_awt_windows_WToolkit_init@8, address_out = 0x6fb72210 True 1
Fn
Module Load module_name = COMCTL32.dll, base_address = 0x74110000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll, function = InitCommonControlsEx, address_out = 0x741309ce True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = LoadIconW, address_out = 0x7588f142 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = RegisterClassW, address_out = 0x7588ed4a True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = GetDC, address_out = 0x7589544c True 1
Fn
Module Load module_name = GDI32.dll, base_address = 0x75ec0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\gdi32.dll, function = GetDeviceCaps, address_out = 0x75ec6f7f True 2
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = ReleaseDC, address_out = 0x75895421 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = CreateWindowExW, address_out = 0x7588ec7c True 1
Fn
Window Create window_name = theAwtToolkitWindow, class_name = SunAwtToolkit, wndproc_parameter = 0 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = DefWindowProcW, address_out = 0x7589507d True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = SetWindowsHookExW, address_out = 0x7588e30c True 1
Fn
System Register Hook type = WH_GETMESSAGE, hookproc_address = 0x6fb71da0 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = OleInitialize, address_out = 0x75caefd7 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 569, size_out = 569 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 333, size_out = 333 True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\user32.dll, function = PeekMessageW, address_out = 0x7589634a True 1
Fn
Thread 0x6ac
298 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 16, size_out = 16 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Local\Temp\_0.98963488192277293018538009244777557.class, size = 390, size_out = 390 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 448, size_out = 448 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4013, size_out = 4013 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1566, size_out = 1566 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 402, size_out = 402 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1366, size_out = 1366 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 9311, size_out = 9311 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3572, size_out = 3572 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1619, size_out = 1619 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2404, size_out = 2404 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3013, size_out = 3013 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1708, size_out = 1708 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2879, size_out = 2879 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1285, size_out = 1285 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1398, size_out = 1398 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1090, size_out = 1090 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:11 (UTC) True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3789, size_out = 3789 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 436, size_out = 436 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 792, size_out = 792 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 384, size_out = 384 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 78, size_out = 78 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1217, size_out = 1217 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 480, size_out = 480 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 622, size_out = 622 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 76, size_out = 76 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 527, size_out = 527 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4051, size_out = 4051 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7991, size_out = 7991 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 704, size_out = 704 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8401, size_out = 8401 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2096, size_out = 2096 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2691, size_out = 2691 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1111, size_out = 1111 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1664, size_out = 1664 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 6028, size_out = 6028 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7832, size_out = 7832 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 382, size_out = 382 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5512, size_out = 5512 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 949, size_out = 949 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1167, size_out = 1167 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1731, size_out = 1731 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1427, size_out = 1427 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1429, size_out = 1429 True 1
Fn
Data
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, os_pid = 0x7a0, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1873, size_out = 1873 True 1
Fn
Data
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, type = file_attributes False 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, FILE_FLAG_OPEN_REPARSE_POINT, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Write filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, size = 281 True 1
Fn
Data
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
File Create Pipe pipe_name = Anonymous read pipe, size = 4120 True 1
Fn
Process Create process_name = cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, os_pid = 0x624, creation_flags = CREATE_UNICODE_ENVIRONMENT, CREATE_NO_WINDOW, startup_flags = STARTF_USESTDHANDLES, show_window = SW_HIDE True 1
Fn
File Read size = 8192, size_out = 108 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Get Info type = file_type True 1
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
File Read size = 8192, size_out = 0 False 1
Fn
Process Terminate exit_code = 1 False 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, type = file_attributes True 1
Fn
File Delete filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\javaw.exe, type = file_attributes True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1396, size_out = 1396 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 582, size_out = 582 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 46400, size_out = 46400 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 263, size_out = 263 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 357, size_out = 357 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5472, size_out = 5472 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3241, size_out = 3241 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 784, size_out = 784 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1886, size_out = 1886 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5529, size_out = 5529 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1188, size_out = 1188 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 213, size_out = 213 True 1
Fn
Data
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetFriendlyIfIndex, address_out = 0x7338d855 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetIpAddrTable, address_out = 0x73389bb0 True 1
Fn
Module Get Address module_name = c:\windows\system32\iphlpapi.dll, function = GetAdaptersAddresses, address_out = 0x73386a4d True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 878, size_out = 878 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7520, size_out = 7520 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 8446, size_out = 8446 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\management.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 2
Fn
Module Get Address module_name = Unknown module name, function = _JNI_OnLoad@8, address_out = 0x738e2194 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5830, size_out = 5830 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1929, size_out = 1929 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 519, size_out = 519 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 855, size_out = 855 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 413, size_out = 413 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 300, size_out = 300 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 152, size_out = 152 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1206, size_out = 1206 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 7192, size_out = 7192 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 536, size_out = 536 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 22580, size_out = 22580 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 325, size_out = 325 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2388, size_out = 2388 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1746, size_out = 1746 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 845, size_out = 845 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 14934, size_out = 14934 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 322, size_out = 322 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1032, size_out = 1032 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 773, size_out = 773 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 122, size_out = 122 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM, type = file_attributes True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\ID.txt, type = file_attributes True 1
Fn
File Read size = 8192, size_out = 47 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 47 True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\fUTkALeaTxM\DdWDtpinxpf, type = file_attributes True 4
Fn
Thread 0x6e4
182 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:16 (UTC) True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:19 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:22 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:30 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:33 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:36 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:39 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:42 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:45 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:48 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:51 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:54 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:57 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:00 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:03 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:07 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:10 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:13 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:16 (UTC) True 3
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:19 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:22 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:25 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:28 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:31 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:35 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:38 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:41 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:44 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:47 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:50 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:53 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:56 (UTC) True 2
Fn
System Sleep duration = 2000 milliseconds (2.000 seconds) True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:59 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:02 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:06 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:09 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:12 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:15 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:18 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:21 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:24 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:27 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:30 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:33 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:36 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:40 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:43 (UTC) True 3
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:46 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:49 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:52 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:55 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:58 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:01 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:04 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:07 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:11 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:14 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:17 (UTC) True 2
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:20 (UTC) True 2
Fn
Thread 0x74c
274 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 26461, size_out = 26461 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 4540, size_out = 4540 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1995, size_out = 1995 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\net.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1261, size_out = 1261 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4115, size_out = 4115 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2598, size_out = 2598 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 11029, size_out = 11029 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 296, size_out = 296 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1028, size_out = 1028 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 17440, size_out = 17440 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3033, size_out = 3033 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 861, size_out = 861 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2660, size_out = 2660 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1444, size_out = 1444 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1192, size_out = 1192 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 7071, size_out = 7071 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2038, size_out = 2038 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2049, size_out = 2049 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1627, size_out = 1627 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 8760, size_out = 8760 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3164, size_out = 3164 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 2552, size_out = 2552 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1600, size_out = 1600 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 109, size_out = 109 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 235, size_out = 235 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 2863, size_out = 2863 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 443, size_out = 443 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 837, size_out = 837 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 3196, size_out = 3196 True 1
Fn
Data
File Get Info type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1262, size_out = 1262 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 590, size_out = 590 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 525, size_out = 525 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1320, size_out = 1320 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1812, size_out = 1812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 240, size_out = 240 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1434, size_out = 1434 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 2863, size_out = 2863 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 390, size_out = 390 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 242, size_out = 242 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1989, size_out = 1989 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 837, size_out = 837 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 734, size_out = 734 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 235, size_out = 235 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 5122, size_out = 5122 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 285, size_out = 285 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 889, size_out = 889 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3271, size_out = 3271 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 496, size_out = 496 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunec.jar, size = 1812, size_out = 1812 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 302, size_out = 302 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 23927, size_out = 23927 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1227, size_out = 1227 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 761, size_out = 761 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 107, size_out = 107 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2146, size_out = 2146 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 975, size_out = 975 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 2114, size_out = 2114 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3293, size_out = 3293 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jce.jar, size = 634, size_out = 634 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 725, size_out = 725 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 859, size_out = 859 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 745, size_out = 745 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 1326, size_out = 1326 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 4319, size_out = 4319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 595, size_out = 595 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 626, size_out = 626 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 763, size_out = 763 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 1
Fn
File Create filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, file_attributes = FILE_FLAG_BACKUP_SEMANTICS, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE, FILE_SHARE_DELETE True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = time True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 4, size_out = 4 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 128, size_out = 128 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 2191, size_out = 2191 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 913, size_out = 913 True 2
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 852, size_out = 852 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1319, size_out = 1319 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 103, size_out = 103 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 1269, size_out = 1269 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:13 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:13 (UTC) True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.jar, size = 404, size_out = 404 True 1
Fn
Data
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\x86\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\ext\sunmscapi.dll, type = file_attributes False 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\bin\sunmscapi.dll, type = file_attributes True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:13 (UTC) True 2
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1399, size_out = 1399 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 3618, size_out = 3618 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1507, size_out = 1507 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 8099, size_out = 8099 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 964, size_out = 964 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 1312, size_out = 1312 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\jsse.jar, size = 5799, size_out = 5799 True 1
Fn
Data
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 686, size_out = 686 True 1
Fn
Data
System Get Time type = System Time, time = 1627-02-05 14:07:13 (UTC) True 1
Fn
File Get Info filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\net.properties, type = file_attributes True 2
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:13 (UTC) True 1
Fn
File Read size = 8192, size_out = 3070 True 1
Fn
Data
File Get Info type = file_type True 1
Fn
File Get Info type = size, size_out = 3070 True 1
Fn
File Read size = 8192, size_out = 0 True 1
Fn
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 3605, size_out = 3605 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 331, size_out = 331 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 160, size_out = 160 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 30, size_out = 30 True 1
Fn
Data
File Read filename = C:\Users\2XC7u663GxWc\AppData\Roaming\Oracle\lib\rt.jar, size = 278, size_out = 278 True 1
Fn
Data
Socket Close type = SOCK_STREAM True 1
Fn
Thread 0x274
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:17 (UTC) True 1
Fn
Thread 0x768
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 1627-02-05 14:07:20 (UTC) True 1
Fn
Thread 0x564
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:27 (UTC) True 1
Fn
Thread 0x784
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:31 (UTC) True 1
Fn
Thread 0x46c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:34 (UTC) True 1
Fn
Thread 0x57c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:37 (UTC) True 1
Fn
Thread 0x774
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:40 (UTC) True 1
Fn
Thread 0x188
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:43 (UTC) True 1
Fn
Thread 0x318
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x230
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x5d8
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:46 (UTC) True 1
Fn
Thread 0x30c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:49 (UTC) True 1
Fn
Thread 0x574
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:52 (UTC) True 1
Fn
Thread 0x624
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:55 (UTC) True 1
Fn
Thread 0x718
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:51:58 (UTC) True 1
Fn
Thread 0x7a0
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:01 (UTC) True 1
Fn
Thread 0x274
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:05 (UTC) True 1
Fn
Thread 0x7ac
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:08 (UTC) True 1
Fn
Thread 0x7a8
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:11 (UTC) True 1
Fn
Thread 0x768
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:14 (UTC) True 1
Fn
Thread 0x64
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:17 (UTC) True 1
Fn
Thread 0x564
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:20 (UTC) True 1
Fn
Thread 0x154
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:23 (UTC) True 1
Fn
Thread 0x784
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:26 (UTC) True 1
Fn
Thread 0x57c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:29 (UTC) True 1
Fn
Thread 0x174
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:32 (UTC) True 1
Fn
Thread 0x7a4
1 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Thread 0x6ac
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:36 (UTC) True 1
Fn
Thread 0x180
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:39 (UTC) True 1
Fn
Thread 0x718
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:42 (UTC) True 1
Fn
Thread 0x500
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:45 (UTC) True 1
Fn
Thread 0x228
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:48 (UTC) True 1
Fn
Thread 0x6d8
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:51 (UTC) True 1
Fn
Thread 0x2d8
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:54 (UTC) True 1
Fn
Thread 0x218
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:52:57 (UTC) True 1
Fn
Thread 0x64
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:00 (UTC) True 1
Fn
Thread 0x728
3 0
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:03 (UTC) True 2
Fn
Thread 0x340
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:04 (UTC) True 1
Fn
Thread 0x638
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:07 (UTC) True 1
Fn
Thread 0x790
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:10 (UTC) True 1
Fn
Thread 0x6ac
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:13 (UTC) True 1
Fn
Thread 0x180
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:16 (UTC) True 1
Fn
Thread 0x658
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:19 (UTC) True 1
Fn
Thread 0x718
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:22 (UTC) True 1
Fn
Thread 0x66c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:25 (UTC) True 1
Fn
Thread 0x46c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:28 (UTC) True 1
Fn
Thread 0x76c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:31 (UTC) True 1
Fn
Thread 0x228
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:34 (UTC) True 1
Fn
Thread 0x6d8
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:37 (UTC) True 1
Fn
Thread 0x244
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:41 (UTC) True 1
Fn
Thread 0x210
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:44 (UTC) True 1
Fn
Thread 0x260
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:47 (UTC) True 1
Fn
Thread 0x64
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:50 (UTC) True 1
Fn
Thread 0x70c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:53 (UTC) True 1
Fn
Thread 0x71c
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:56 (UTC) True 1
Fn
Thread 0x4b4
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:53:59 (UTC) True 1
Fn
Thread 0xb0
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:02 (UTC) True 1
Fn
Thread 0x124
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:05 (UTC) True 1
Fn
Thread 0x638
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:08 (UTC) True 1
Fn
Thread 0x778
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:12 (UTC) True 1
Fn
Thread 0x740
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:15 (UTC) True 1
Fn
Thread 0x690
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:18 (UTC) True 1
Fn
Thread 0x768
2 2
»
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Socket Create protocol = IPPROTO_IP, address_family = AF_INET6, type = SOCK_STREAM True 1
Fn
Socket Close type = SOCK_STREAM True 1
Fn
System Get Time type = System Time, time = 2018-07-19 09:54:21 (UTC) True 1
Fn
Process #32: cmd.exe
58 0
»
Information Value
ID #32
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:04, Reason: Child Process
Unmonitor End Time: 00:02:05, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x558
Parent PID 0x35c (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 718
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000d0000 0x000d0000 0x000d1fff Pagefile Backed Memory - True - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x001effff Private Memory - True - False -
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory - True - False -
cscript.exe.mui 0x00200000 0x00202fff Memory Mapped File - False - False -
private_0x00000000002a0000 0x002a0000 0x002affff Private Memory - True - False -
cscript.exe 0x002b0000 0x002d1fff Memory Mapped File - False - False -
private_0x0000000000370000 0x00370000 0x0046ffff Private Memory - True - False -
pagefile_0x0000000000470000 0x00470000 0x00537fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000540000 0x00540000 0x00640fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000650000 0x00650000 0x0124ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001250000 0x01250000 0x014dafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x014e0000 0x017aefff Memory Mapped File - False - False -
cmd.exe 0x4a710000 0x4a75bfff Memory Mapped File - True - False -
winbrand.dll 0x6fad0000 0x6fad6fff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x718
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
System Get Time type = Ticks, time = 32167 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a710000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Windows\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x755dac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x755e3ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x755f2732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x7a4, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #33: cscript.exe
93 0
»
Information Value
ID #33
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:04, Reason: Child Process
Unmonitor End Time: 00:02:05, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x7a4
Parent PID 0x558 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 46C
0x 7A0
0x 79C
0x 78C
0x 784
0x 6B4
0x 6B0
0x 6AC
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
cscript.exe 0x00100000 0x0010bfff Memory Mapped File - True - False -
pagefile_0x0000000000110000 0x00110000 0x00110fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000120000 0x00120000 0x00120fff Pagefile Backed Memory - True - False -
private_0x0000000000130000 0x00130000 0x0022ffff Private Memory - True - False -
rpcss.dll 0x00230000 0x0028bfff Memory Mapped File - False - False -
retrive1360789152958718586.vbs 0x00230000 0x00230fff Memory Mapped File - True - False -
rsaenh.dll 0x00230000 0x0026bfff Memory Mapped File - False - False -
private_0x0000000000230000 0x00230000 0x0023ffff Private Memory - True - False -
retrive1360789152958718586.vbs 0x00240000 0x00240fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00240000 0x0024efff Memory Mapped File - False - False -
cscript.exe 0x002b0000 0x002d1fff Memory Mapped File - True - False -
private_0x00000000003a0000 0x003a0000 0x0049ffff Private Memory - True - False -
pagefile_0x00000000004a0000 0x004a0000 0x00567fff Pagefile Backed Memory - True - False -
private_0x0000000000600000 0x00600000 0x0060ffff Private Memory - True - False -
pagefile_0x0000000000610000 0x00610000 0x00710fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000720000 0x00720000 0x0131ffff Pagefile Backed Memory - True - False -
private_0x0000000001320000 0x01320000 0x0141ffff Private Memory - True - False -
pagefile_0x0000000001420000 0x01420000 0x014fefff Pagefile Backed Memory - True - False -
private_0x0000000001560000 0x01560000 0x0165ffff Private Memory - True - False -
sortdefault.nls 0x01660000 0x0192efff Memory Mapped File - False - False -
private_0x0000000001970000 0x01970000 0x01a6ffff Private Memory - True - False -
private_0x0000000001a80000 0x01a80000 0x01b7ffff Private Memory - True - False -
pagefile_0x0000000001b80000 0x01b80000 0x01f7ffff Pagefile Backed Memory - True - False -
private_0x0000000001f80000 0x01f80000 0x0212ffff Private Memory - True - False -
private_0x0000000001f80000 0x01f80000 0x0207ffff Private Memory - True - False -
private_0x0000000002120000 0x02120000 0x0212ffff Private Memory - True - False -
private_0x0000000002160000 0x02160000 0x0225ffff Private Memory - True - False -
private_0x0000000002260000 0x02260000 0x0232ffff Private Memory - True - False -
private_0x0000000002330000 0x02330000 0x0241ffff Private Memory - True - False -
private_0x0000000002440000 0x02440000 0x0253ffff Private Memory - True - False -
private_0x0000000002550000 0x02550000 0x0264ffff Private Memory - True - False -
private_0x0000000002660000 0x02660000 0x0275ffff Private Memory - True - False -
wbemdisp.dll 0x6f9c0000 0x6f9f0fff Memory Mapped File - True - False -
scrobj.dll 0x6fa00000 0x6fa2cfff Memory Mapped File - True - False -
wshext.dll 0x6fa30000 0x6fa45fff Memory Mapped File - True - False -
msisip.dll 0x6fa50000 0x6fa57fff Memory Mapped File - False - False -
vbscript.dll 0x6fa60000 0x6facafff Memory Mapped File - True - False -
wmiutils.dll 0x709f0000 0x70a06fff Memory Mapped File - False - False -
wbemsvc.dll 0x70ae0000 0x70aeefff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x70f40000 0x70f9bfff Memory Mapped File - False - False -
comctl32.dll 0x72c00000 0x72c83fff Memory Mapped File - False - False -
dwmapi.dll 0x73c60000 0x73c72fff Memory Mapped File - False - False -
uxtheme.dll 0x73f90000 0x73fcffff Memory Mapped File - False - False -
version.dll 0x74680000 0x74688fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
sxs.dll 0x75090000 0x750eefff Memory Mapped File - False - False -
rpcrtremote.dll 0x75120000 0x7512dfff Memory Mapped File - False - False -
msasn1.dll 0x751a0000 0x751abfff Memory Mapped File - False - False -
crypt32.dll 0x751b0000 0x752ccfff Memory Mapped File - False - False -
wintrust.dll 0x752d0000 0x752fcfff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
clbcatq.dll 0x76060000 0x760e2fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
shell32.dll 0x76350000 0x76f99fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x46c
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
System Get Time type = Ticks, time = 32229 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0x2b0000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 196, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x755f4157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 104, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 104, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 16, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x75cd9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 32292 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x75e12102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x75e13352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x75e13825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1360789152958718586.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x75cd6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x75c9cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x75dfca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x75c9c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x79c
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 6300448 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 6300448 False 1
Fn
Process #35: cmd.exe
58 0
»
Information Value
ID #35
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:04, Reason: Child Process
Unmonitor End Time: 00:02:05, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x42c
Parent PID 0x35c (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\javaw.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 134
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory - True - False -
private_0x0000000000060000 0x00060000 0x0015ffff Private Memory - True - False -
locale.nls 0x00160000 0x001c6fff Memory Mapped File - False - False -
pagefile_0x00000000001d0000 0x001d0000 0x001d1fff Pagefile Backed Memory - True - False -
private_0x00000000001e0000 0x001e0000 0x001e0fff Private Memory - True - False -
private_0x00000000001f0000 0x001f0000 0x001f0fff Private Memory - True - False -
private_0x0000000000200000 0x00200000 0x002fffff Private Memory - True - False -
pagefile_0x0000000000300000 0x00300000 0x003c7fff Pagefile Backed Memory - True - False -
private_0x00000000003d0000 0x003d0000 0x003dffff Private Memory - True - False -
pagefile_0x00000000003e0000 0x003e0000 0x004e0fff Pagefile Backed Memory - True - False -
pagefile_0x00000000004f0000 0x004f0000 0x010effff Pagefile Backed Memory - True - False -
pagefile_0x00000000010f0000 0x010f0000 0x0137afff Pagefile Backed Memory - True - False -
sortdefault.nls 0x01380000 0x0164efff Memory Mapped File - False - False -
cscript.exe 0x01650000 0x01671fff Memory Mapped File - False - False -
cscript.exe.mui 0x01680000 0x01682fff Memory Mapped File - False - False -
cmd.exe 0x4a710000 0x4a75bfff Memory Mapped File - True - False -
winbrand.dll 0x6fac0000 0x6fac6fff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x134
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
System Get Time type = Ticks, time = 32557 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a710000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Windows\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x755dac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x755e3ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x755f2732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x174, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #36: cscript.exe
92 0
»
Information Value
ID #36
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:04, Reason: Child Process
Unmonitor End Time: 00:02:05, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x174
Parent PID 0x42c (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 15C
0x 230
0x 574
0x 30C
0x 76C
0x 774
0x 778
0x 640
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
private_0x0000000000100000 0x00100000 0x0010ffff Private Memory - True - False -
pagefile_0x0000000000110000 0x00110000 0x001d7fff Pagefile Backed Memory - True - False -
cscript.exe 0x001e0000 0x001ebfff Memory Mapped File - True - False -
pagefile_0x00000000001f0000 0x001f0000 0x001f0fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000200000 0x00200000 0x00200fff Pagefile Backed Memory - True - False -
private_0x0000000000210000 0x00210000 0x0030ffff Private Memory - True - False -
pagefile_0x0000000000310000 0x00310000 0x00410fff Pagefile Backed Memory - True - False -
rpcss.dll 0x00420000 0x0047bfff Memory Mapped File - False - False -
retrive3549377093237930864.vbs 0x00420000 0x00420fff Memory Mapped File - True - False -
rsaenh.dll 0x00420000 0x0045bfff Memory Mapped File - False - False -
private_0x0000000000420000 0x00420000 0x0042ffff Private Memory - True - False -
retrive3549377093237930864.vbs 0x00430000 0x00430fff Memory Mapped File - True - False -
wbemdisp.tlb 0x00430000 0x0043efff Memory Mapped File - False - False -
private_0x00000000004f0000 0x004f0000 0x005effff Private Memory - True - False -
private_0x00000000005f0000 0x005f0000 0x0073ffff Private Memory - True - False -
pagefile_0x00000000005f0000 0x005f0000 0x006cefff Pagefile Backed Memory - True - False -
private_0x0000000000700000 0x00700000 0x0073ffff Private Memory - True - False -
private_0x0000000000760000 0x00760000 0x0085ffff Private Memory - True - False -
sortdefault.nls 0x00860000 0x00b2efff Memory Mapped File - False - False -
private_0x0000000000b80000 0x00b80000 0x00c7ffff Private Memory - True - False -
private_0x0000000000cb0000 0x00cb0000 0x00daffff Private Memory - True - False -
private_0x0000000000db0000 0x00db0000 0x00eaffff Private Memory - True - False -
cscript.exe 0x00ec0000 0x00ee1fff Memory Mapped File - True - False -
pagefile_0x0000000000ef0000 0x00ef0000 0x01aeffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001af0000 0x01af0000 0x01eeffff Pagefile Backed Memory - True - False -
private_0x0000000001ef0000 0x01ef0000 0x0202ffff Private Memory - True - False -
private_0x0000000001ef0000 0x01ef0000 0x01feffff Private Memory - True - False -
private_0x0000000001ff0000 0x01ff0000 0x0202ffff Private Memory - True - False -
private_0x0000000002040000 0x02040000 0x0213ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0232ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0227ffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0223ffff Private Memory - True - False -
private_0x0000000002240000 0x02240000 0x0227ffff Private Memory - True - False -
private_0x0000000002320000 0x02320000 0x0232ffff Private Memory - True - False -
private_0x0000000002410000 0x02410000 0x0250ffff Private Memory - True - False -
wbemdisp.dll 0x6f9a0000 0x6f9d0fff Memory Mapped File - True - False -
scrobj.dll 0x6f9e0000 0x6fa0cfff Memory Mapped File - True - False -
wshext.dll 0x6fa10000 0x6fa25fff Memory Mapped File - True - False -
vbscript.dll 0x6fa50000 0x6fabafff Memory Mapped File - True - False -
msisip.dll 0x6fad0000 0x6fad7fff Memory Mapped File - False - False -
wmiutils.dll 0x709f0000 0x70a06fff Memory Mapped File - False - False -
wbemsvc.dll 0x70ae0000 0x70aeefff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x70f40000 0x70f9bfff Memory Mapped File - False - False -
comctl32.dll 0x72c00000 0x72c83fff Memory Mapped File - False - False -
dwmapi.dll 0x73c60000 0x73c72fff Memory Mapped File - False - False -
uxtheme.dll 0x73f90000 0x73fcffff Memory Mapped File - False - False -
version.dll 0x74680000 0x74688fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
sxs.dll 0x75090000 0x750eefff Memory Mapped File - False - False -
rpcrtremote.dll 0x75120000 0x7512dfff Memory Mapped File - False - False -
msasn1.dll 0x751a0000 0x751abfff Memory Mapped File - False - False -
crypt32.dll 0x751b0000 0x752ccfff Memory Mapped File - False - False -
wintrust.dll 0x752d0000 0x752fcfff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
clbcatq.dll 0x76060000 0x760e2fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
shell32.dll 0x76350000 0x76f99fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x15c
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:09 (UTC) True 1
Fn
System Get Time type = Ticks, time = 32604 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0xec0000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 132, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 132, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 132, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x755f4157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 89, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 89, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 208, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 208, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x75cd9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 32651 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x75e12102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x75e13352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x75e13825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive3549377093237930864.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x75cd6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x75c9cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x75dfca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x75c9c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x574
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 1057568 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 1057568 False 1
Fn
Process #37: cmd.exe
58 0
»
Information Value
ID #37
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:06, Reason: Child Process
Unmonitor End Time: 00:02:07, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x7a0
Parent PID 0x290 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 784
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000050000 0x00050000 0x00056fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000060000 0x00060000 0x00061fff Pagefile Backed Memory - True - False -
private_0x0000000000070000 0x00070000 0x00070fff Private Memory - True - False -
private_0x0000000000080000 0x00080000 0x00080fff Private Memory - True - False -
cscript.exe.mui 0x00090000 0x00092fff Memory Mapped File - False - False -
private_0x00000000000b0000 0x000b0000 0x001affff Private Memory - True - False -
cscript.exe 0x001b0000 0x001d1fff Memory Mapped File - False - False -
private_0x00000000001f0000 0x001f0000 0x002effff Private Memory - True - False -
locale.nls 0x002f0000 0x00356fff Memory Mapped File - False - False -
pagefile_0x0000000000360000 0x00360000 0x00427fff Pagefile Backed Memory - True - False -
private_0x0000000000510000 0x00510000 0x0051ffff Private Memory - True - False -
pagefile_0x0000000000520000 0x00520000 0x00620fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000630000 0x00630000 0x0122ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001230000 0x01230000 0x014bafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x014c0000 0x0178efff Memory Mapped File - False - False -
cmd.exe 0x4a540000 0x4a58bfff Memory Mapped File - True - False -
winbrand.dll 0x738d0000 0x738d6fff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x784
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:11 (UTC) True 1
Fn
System Get Time type = Ticks, time = 34585 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a540000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Windows\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x755dac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x755e3ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x755f2732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x718, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #38: cscript.exe
93 0
»
Information Value
ID #38
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:06, Reason: Child Process
Unmonitor End Time: 00:02:07, Reason: Self Terminated
Monitor Duration 00:00:01
OS Process Information
»
Information Value
PID 0x718
Parent PID 0x7a0 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 790
0x 274
0x 544
0x 74C
0x 768
0x 564
0x 638
0x 6D0
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
locale.nls 0x00040000 0x000a6fff Memory Mapped File - False - False -
pagefile_0x00000000000b0000 0x000b0000 0x000b6fff Pagefile Backed Memory - True - False -
pagefile_0x00000000000c0000 0x000c0000 0x000c1fff Pagefile Backed Memory - True - False -
cscript.exe.mui 0x000d0000 0x000d2fff Memory Mapped File - False - False -
private_0x00000000000e0000 0x000e0000 0x000e0fff Private Memory - True - False -
private_0x00000000000f0000 0x000f0000 0x000f0fff Private Memory - True - False -
private_0x0000000000100000 0x00100000 0x001fffff Private Memory - True - False -
rpcss.dll 0x00200000 0x0025bfff Memory Mapped File - False - False -
cscript.exe 0x00200000 0x0020bfff Memory Mapped File - True - False -
pagefile_0x0000000000210000 0x00210000 0x00210fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000220000 0x00220000 0x00220fff Pagefile Backed Memory - True - False -
retrive7366168634408503799.vbs 0x00230000 0x00230fff Memory Mapped File - True - False -
rsaenh.dll 0x00230000 0x0026bfff Memory Mapped File - False - False -
private_0x0000000000230000 0x00230000 0x0023ffff Private Memory - True - False -
retrive7366168634408503799.vbs 0x00240000 0x00240fff Memory Mapped File r True True False
wbemdisp.tlb 0x00240000 0x0024efff Memory Mapped File - False - False -
private_0x0000000000270000 0x00270000 0x0027ffff Private Memory - True - False -
private_0x00000000002a0000 0x002a0000 0x0039ffff Private Memory - True - False -
pagefile_0x00000000003a0000 0x003a0000 0x00467fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000470000 0x00470000 0x00570fff Pagefile Backed Memory - True - False -
private_0x0000000000580000 0x00580000 0x006affff Private Memory - True - False -
pagefile_0x0000000000580000 0x00580000 0x0065efff Pagefile Backed Memory - True - False -
private_0x0000000000670000 0x00670000 0x006affff Private Memory - True - False -
private_0x0000000000770000 0x00770000 0x0086ffff Private Memory - True - False -
cscript.exe 0x00870000 0x00891fff Memory Mapped File - True - False -
pagefile_0x00000000008a0000 0x008a0000 0x0149ffff Pagefile Backed Memory - True - False -
sortdefault.nls 0x014a0000 0x0176efff Memory Mapped File - False - False -
private_0x0000000001780000 0x01780000 0x0187ffff Private Memory - True - False -
private_0x0000000001960000 0x01960000 0x01a5ffff Private Memory - True - False -
private_0x0000000001ad0000 0x01ad0000 0x01bcffff Private Memory - True - False -
pagefile_0x0000000001bd0000 0x01bd0000 0x01fcffff Pagefile Backed Memory - True - False -
private_0x0000000001fd0000 0x01fd0000 0x020bffff Private Memory - True - False -
private_0x00000000020c0000 0x020c0000 0x021bffff Private Memory - True - False -
private_0x00000000021c0000 0x021c0000 0x022affff Private Memory - True - False -
private_0x00000000022b0000 0x022b0000 0x0241ffff Private Memory - True - False -
private_0x0000000002420000 0x02420000 0x0251ffff Private Memory - True - False -
private_0x0000000002580000 0x02580000 0x0267ffff Private Memory - True - False -
private_0x0000000002820000 0x02820000 0x0291ffff Private Memory - True - False -
wmiutils.dll 0x709f0000 0x70a06fff Memory Mapped File - False - False -
wbemsvc.dll 0x70ae0000 0x70aeefff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x70f40000 0x70f9bfff Memory Mapped File - False - False -
wbemdisp.dll 0x72780000 0x727b0fff Memory Mapped File - True - False -
scrobj.dll 0x727c0000 0x727ecfff Memory Mapped File - True - False -
comctl32.dll 0x727f0000 0x72873fff Memory Mapped File - False - False -
wshext.dll 0x72c00000 0x72c15fff Memory Mapped File - True - False -
vbscript.dll 0x72c20000 0x72c8afff Memory Mapped File - True - False -
msisip.dll 0x738c0000 0x738c7fff Memory Mapped File - False - False -
dwmapi.dll 0x73c60000 0x73c72fff Memory Mapped File - False - False -
uxtheme.dll 0x73f90000 0x73fcffff Memory Mapped File - False - False -
version.dll 0x74680000 0x74688fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
sxs.dll 0x75090000 0x750eefff Memory Mapped File - False - False -
rpcrtremote.dll 0x75120000 0x7512dfff Memory Mapped File - False - False -
msasn1.dll 0x751a0000 0x751abfff Memory Mapped File - False - False -
crypt32.dll 0x751b0000 0x752ccfff Memory Mapped File - False - False -
wintrust.dll 0x752d0000 0x752fcfff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
clbcatq.dll 0x76060000 0x760e2fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
shell32.dll 0x76350000 0x76f99fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd5000 0x7ffd5000 0x7ffd5fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x790
91 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:11 (UTC) True 1
Fn
System Get Time type = Ticks, time = 34647 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0x870000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 228, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x755f4157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 148, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 148, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 48, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x75cd9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 34694 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, protection = PAGE_READONLY, maximum_size = 276 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x75e12102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x75e13352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x75e13825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive7366168634408503799.vbs, size = 276, size_out = 276 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x75cd6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x75c9cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x75dfca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x75c9c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x544
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 2564896 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 2564896 False 1
Fn
Process #39: cmd.exe
58 0
»
Information Value
ID #39
File Name c:\windows\system32\cmd.exe
Command Line cmd.exe /C cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:06, Reason: Child Process
Unmonitor End Time: 00:02:08, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0x624
Parent PID 0x290 (c:\users\2xc7u663gxwc\appdata\roaming\oracle\bin\java.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 5D8
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000040000 0x00040000 0x00040fff Pagefile Backed Memory - True - False -
locale.nls 0x00050000 0x000b6fff Memory Mapped File - False - False -
pagefile_0x00000000000c0000 0x000c0000 0x00187fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000190000 0x00190000 0x00196fff Pagefile Backed Memory - True - False -
pagefile_0x00000000001a0000 0x001a0000 0x001a1fff Pagefile Backed Memory - True - False -
private_0x00000000001b0000 0x001b0000 0x001b0fff Private Memory - True - False -
private_0x00000000001c0000 0x001c0000 0x001c0fff Private Memory - True - False -
cscript.exe.mui 0x001d0000 0x001d2fff Memory Mapped File - False - False -
private_0x00000000001e0000 0x001e0000 0x002dffff Private Memory - True - False -
cscript.exe 0x002e0000 0x00301fff Memory Mapped File - False - False -
private_0x0000000000390000 0x00390000 0x0048ffff Private Memory - True - False -
pagefile_0x0000000000490000 0x00490000 0x00590fff Pagefile Backed Memory - True - False -
private_0x0000000000650000 0x00650000 0x0065ffff Private Memory - True - False -
pagefile_0x0000000000660000 0x00660000 0x0125ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000001260000 0x01260000 0x014eafff Pagefile Backed Memory - True - False -
sortdefault.nls 0x014f0000 0x017befff Memory Mapped File - False - False -
cmd.exe 0x4a540000 0x4a58bfff Memory Mapped File - True - False -
winbrand.dll 0x738c0000 0x738c6fff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x5d8
58 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
System Get Time type = Ticks, time = 34944 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cmd.exe, base_address = 0x4a540000 True 1
Fn
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Environment Get Environment String - True 2
Fn
Data
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 64, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor, value_name = AutoRun, data = 64, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DisableUNCCheck, data = 64, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = EnableExtensions, data = 1, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DelayedExpansion, data = 1, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = DefaultColor, data = 0, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = CompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = PathCompletionChar, data = 9, type = REG_DWORD_LITTLE_ENDIAN True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Command Processor, value_name = AutoRun, data = 9, type = REG_NONE False 1
Fn
Module Get Filename process_name = c:\windows\system32\cmd.exe, file_name_orig = C:\Windows\system32\cmd.exe, size = 260 True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Environment Get Environment String name = PROMPT False 1
Fn
Environment Set Environment String name = PROMPT, value = $P$G True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Get Environment String name = COMSPEC, result_out = C:\Windows\system32\cmd.exe True 1
Fn
Environment Get Environment String name = KEYS False 1
Fn
File Get Info filename = C:\Windows\system32, type = file_attributes True 1
Fn
File Get Info filename = C:\Windows\System32, type = file_attributes True 1
Fn
Environment Set Environment String name = =C:, value = C:\Windows\System32 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Module Get Handle module_name = c:\windows\system32\kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = CopyFileExW, address_out = 0x755dac6c True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = IsDebuggerPresent, address_out = 0x755e3ea8 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetConsoleInputExeNameW, address_out = 0x755f2732 True 1
Fn
File Get Info filename = cscript.exe, type = file_attributes True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Environment Get Environment String name = PATHEXT, result_out = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC True 1
Fn
Process Create process_name = C:\Windows\system32\cscript.exe, os_pid = 0x640, creation_flags = CREATE_EXTENDED_STARTUPINFO_PRESENT, show_window = SW_SHOWNORMAL True 1
Fn
Environment Set Environment String name = COPYCMD True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCode, value = 00000000 True 1
Fn
Environment Get Environment String - True 1
Fn
Data
Environment Set Environment String name = =ExitCodeAscii True 1
Fn
Environment Get Environment String - True 1
Fn
Data
File Open filename = STD_OUTPUT_HANDLE True 2
Fn
File Open filename = STD_INPUT_HANDLE True 1
Fn
Process #40: cscript.exe
92 0
»
Information Value
ID #40
File Name c:\windows\system32\cscript.exe
Command Line cscript.exe C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs
Initial Working Directory C:\Windows\system32\
Monitor Start Time: 00:02:06, Reason: Child Process
Unmonitor End Time: 00:02:08, Reason: Self Terminated
Monitor Duration 00:00:02
OS Process Information
»
Information Value
PID 0x640
Parent PID 0x624 (c:\windows\system32\cmd.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username ZGW5TDPU\2XC7u663GxWc
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 230
0x 76C
0x 774
0x 778
0x 15C
0x 188
0x 318
0x 6B0
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory - True - False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000020000 0x00020000 0x0002ffff Pagefile Backed Memory - True - False -
pagefile_0x0000000000030000 0x00030000 0x00033fff Pagefile Backed Memory - True - False -
cscript.exe 0x00040000 0x00061fff Memory Mapped File - True - False -
pagefile_0x0000000000070000 0x00070000 0x00076fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000080000 0x00080000 0x00081fff Pagefile Backed Memory - True - False -
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory - True - False -
locale.nls 0x00190000 0x001f6fff Memory Mapped File - False - False -
cscript.exe.mui 0x00200000 0x00202fff Memory Mapped File - False - False -
private_0x0000000000210000 0x00210000 0x00210fff Private Memory - True - False -
private_0x0000000000220000 0x00220000 0x00220fff Private Memory - True - False -
rpcss.dll 0x00230000 0x0028bfff Memory Mapped File - False - False -
cscript.exe 0x00230000 0x0023bfff Memory Mapped File - True - False -
pagefile_0x0000000000240000 0x00240000 0x00240fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000250000 0x00250000 0x00250fff Pagefile Backed Memory - True - False -
retrive1162148989861803484.vbs 0x00260000 0x00260fff Memory Mapped File - True - False -
rsaenh.dll 0x00260000 0x0029bfff Memory Mapped File - False - False -
private_0x0000000000260000 0x00260000 0x0026ffff Private Memory - True - False -
retrive1162148989861803484.vbs 0x00270000 0x00270fff Memory Mapped File r True True False
wbemdisp.tlb 0x00270000 0x0027efff Memory Mapped File - False - False -
private_0x00000000002a0000 0x002a0000 0x0039ffff Private Memory - True - False -
pagefile_0x00000000003a0000 0x003a0000 0x00467fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000470000 0x00470000 0x0054efff Pagefile Backed Memory - True - False -
private_0x0000000000570000 0x00570000 0x0057ffff Private Memory - True - False -
pagefile_0x0000000000580000 0x00580000 0x00680fff Pagefile Backed Memory - True - False -
pagefile_0x0000000000690000 0x00690000 0x0128ffff Pagefile Backed Memory - True - False -
private_0x0000000001290000 0x01290000 0x0143ffff Private Memory - True - False -
private_0x00000000012c0000 0x012c0000 0x013bffff Private Memory - True - False -
private_0x0000000001400000 0x01400000 0x0143ffff Private Memory - True - False -
private_0x0000000001490000 0x01490000 0x0158ffff Private Memory - True - False -
sortdefault.nls 0x01590000 0x0185efff Memory Mapped File - False - False -
private_0x00000000018e0000 0x018e0000 0x019dffff Private Memory - True - False -
pagefile_0x00000000019e0000 0x019e0000 0x01ddffff Pagefile Backed Memory - True - False -
private_0x0000000001ed0000 0x01ed0000 0x01fcffff Private Memory - True - False -
private_0x0000000001fd0000 0x01fd0000 0x0214ffff Private Memory - True - False -
private_0x0000000001fd0000 0x01fd0000 0x020cffff Private Memory - True - False -
private_0x0000000002140000 0x02140000 0x0214ffff Private Memory - True - False -
private_0x0000000002150000 0x02150000 0x0226ffff Private Memory - True - False -
private_0x0000000002270000 0x02270000 0x0247ffff Private Memory - True - False -
private_0x0000000002270000 0x02270000 0x0236ffff Private Memory - True - False -
private_0x0000000002440000 0x02440000 0x0247ffff Private Memory - True - False -
private_0x0000000002570000 0x02570000 0x0266ffff Private Memory - True - False -
private_0x00000000027e0000 0x027e0000 0x028dffff Private Memory - True - False -
wmiutils.dll 0x709f0000 0x70a06fff Memory Mapped File - False - False -
wbemsvc.dll 0x70ae0000 0x70aeefff Memory Mapped File - False - False -
wbemprox.dll 0x70d40000 0x70d49fff Memory Mapped File - False - False -
ntdsapi.dll 0x70d50000 0x70d67fff Memory Mapped File - False - False -
fastprox.dll 0x70d70000 0x70e05fff Memory Mapped File - False - False -
wbemcomn.dll 0x70f40000 0x70f9bfff Memory Mapped File - False - False -
comctl32.dll 0x72780000 0x72803fff Memory Mapped File - False - False -
vbscript.dll 0x72810000 0x7287afff Memory Mapped File - True - False -
wbemdisp.dll 0x72c00000 0x72c30fff Memory Mapped File - True - False -
scrobj.dll 0x72c40000 0x72c6cfff Memory Mapped File - True - False -
wshext.dll 0x72c70000 0x72c85fff Memory Mapped File - True - False -
msisip.dll 0x738d0000 0x738d7fff Memory Mapped File - False - False -
dwmapi.dll 0x73c60000 0x73c72fff Memory Mapped File - False - False -
uxtheme.dll 0x73f90000 0x73fcffff Memory Mapped File - False - False -
version.dll 0x74680000 0x74688fff Memory Mapped File - False - False -
rsaenh.dll 0x749a0000 0x749dafff Memory Mapped File - False - False -
cryptsp.dll 0x74c00000 0x74c15fff Memory Mapped File - False - False -
cryptbase.dll 0x75080000 0x7508bfff Memory Mapped File - False - False -
sxs.dll 0x75090000 0x750eefff Memory Mapped File - False - False -
rpcrtremote.dll 0x75120000 0x7512dfff Memory Mapped File - False - False -
msasn1.dll 0x751a0000 0x751abfff Memory Mapped File - False - False -
crypt32.dll 0x751b0000 0x752ccfff Memory Mapped File - False - False -
wintrust.dll 0x752d0000 0x752fcfff Memory Mapped File - False - False -
kernelbase.dll 0x753e0000 0x75429fff Memory Mapped File - False - False -
shlwapi.dll 0x75480000 0x754d6fff Memory Mapped File - False - False -
sechost.dll 0x754f0000 0x75508fff Memory Mapped File - False - False -
oleaut32.dll 0x75510000 0x7559efff Memory Mapped File - False - False -
kernel32.dll 0x755a0000 0x75673fff Memory Mapped File - False - False -
user32.dll 0x75880000 0x75948fff Memory Mapped File - False - False -
usp10.dll 0x75950000 0x759ecfff Memory Mapped File - False - False -
ole32.dll 0x75c90000 0x75debfff Memory Mapped File - False - False -
advapi32.dll 0x75df0000 0x75e8ffff Memory Mapped File - False - False -
gdi32.dll 0x75ec0000 0x75f0dfff Memory Mapped File - False - False -
lpk.dll 0x75f10000 0x75f19fff Memory Mapped File - False - False -
clbcatq.dll 0x76060000 0x760e2fff Memory Mapped File - False - False -
nsi.dll 0x76100000 0x76105fff Memory Mapped File - False - False -
msvcrt.dll 0x76110000 0x761bbfff Memory Mapped File - False - False -
rpcrt4.dll 0x761c0000 0x76260fff Memory Mapped File - False - False -
shell32.dll 0x76350000 0x76f99fff Memory Mapped File - False - False -
ws2_32.dll 0x76fa0000 0x76fd4fff Memory Mapped File - False - False -
ntdll.dll 0x76fe0000 0x7711bfff Memory Mapped File - False - False -
imm32.dll 0x77120000 0x7713efff Memory Mapped File - False - False -
msctf.dll 0x77140000 0x7720bfff Memory Mapped File - False - False -
apisetschema.dll 0x77220000 0x77220fff Memory Mapped File - False - False -
pagefile_0x000000007f6f0000 0x7f6f0000 0x7f7effff Pagefile Backed Memory - True - False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory - True - False -
private_0x000000007ffd7000 0x7ffd7000 0x7ffd7fff Private Memory - True - False -
private_0x000000007ffd8000 0x7ffd8000 0x7ffd8fff Private Memory - True - False -
private_0x000000007ffd9000 0x7ffd9000 0x7ffd9fff Private Memory - True - False -
private_0x000000007ffda000 0x7ffda000 0x7ffdafff Private Memory - True - False -
private_0x000000007ffdb000 0x7ffdb000 0x7ffdbfff Private Memory - True - False -
private_0x000000007ffdc000 0x7ffdc000 0x7ffdcfff Private Memory - True - False -
private_0x000000007ffdd000 0x7ffdd000 0x7ffddfff Private Memory - True - False -
private_0x000000007ffde000 0x7ffde000 0x7ffdefff Private Memory - True - False -
private_0x000000007ffdf000 0x7ffdf000 0x7ffdffff Private Memory - True - False -
Threads
Thread 0x230
90 0
»
Category Operation Information Success Count Logfile
System Get Time type = System Time, time = 1627-02-05 14:07:12 (UTC) True 1
Fn
System Get Time type = Ticks, time = 34991 True 1
Fn
Module Get Handle module_name = c:\windows\system32\cscript.exe, base_address = 0x40000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = SetThreadUILanguage, address_out = 0x755f24c2 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 116, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 116, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Enabled, data = 116, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = LogSecuritySuccesses, data = 0, type = REG_NONE False 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x755a0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\kernel32.dll, function = HeapSetInformation, address_out = 0x755f4157 True 1
Fn
Module Get Filename module_name = c:\windows\system32\cscript.exe, process_name = c:\windows\system32\cscript.exe, file_name_orig = C:\Windows\system32\cscript.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = IgnoreUserSettings, data = 237, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 67, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 237, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = TrustPolicy, data = 67, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = UseWINSAFER, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 1, type = REG_SZ True 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = Timeout, data = 192, type = REG_NONE False 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings, value_name = DisplayLogo, data = 49, type = REG_NONE False 1
Fn
File Open filename = STD_OUTPUT_HANDLE True 1
Fn
File Write filename = STD_OUTPUT_HANDLE, size = 108 True 1
Fn
Data
System Sleep duration = -1 (infinite) True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\.vbs True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\.vbs, data = VBSFile, type = REG_SZ True 1
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine True 1
Fn
Registry Read Value reg_name = HKEY_CLASSES_ROOT\VBSFile\ScriptEngine, data = VBScript, type = REG_SZ True 1
Fn
COM Create interface = 00000000-0000-0000-C000-000000000046, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_INPROC_HANDLER, CLSCTX_LOCAL_SERVER, CLSCTX_REMOTE_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75c90000 True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CoCreateInstance, address_out = 0x75cd9d0b True 1
Fn
COM Create interface = 6C736DC1-AB0D-11D0-A2AD-00A0C90F27E8, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Time type = Ticks, time = 35037 True 1
Fn
File Create filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, desired_access = GENERIC_READ, file_attributes = FILE_FLAG_SEQUENTIAL_SCAN, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, type = size True 1
Fn
Module Create Mapping module_name = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, protection = PAGE_READONLY, maximum_size = 281 True 1
Fn
Module Map C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, process_name = c:\windows\system32\cscript.exe, desired_access = FILE_MAP_READ True 1
Fn
Module Unmap process_name = c:\windows\system32\cscript.exe True 1
Fn
System Get Info type = System Directory True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferIdentifyLevel, address_out = 0x75e12102 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferComputeTokenFromLevel, address_out = 0x75e13352 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = SaferCloseLevel, address_out = 0x75e13825 True 1
Fn
System Get Info type = Operating System True 1
Fn
File Get Info filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, type = size True 1
Fn
File Read filename = C:\Users\2XC7U6~1\AppData\Local\Temp\Retrive1162148989861803484.vbs, size = 281, size_out = 281 True 1
Fn
Data
COM Create interface = E4D1C9B0-46E8-11D4-A2A6-00104BD35090, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
System Get Info type = Operating System True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = CreateBindCtx, address_out = 0x75cd6d2c True 1
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = MkParseDisplayName, address_out = 0x75c9cea9 True 1
Fn
System Get Info type = Operating System True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Wbem\Scripting, value_name = Default Impersonation Level, data = 3 True 1
Fn
System Get Info type = System Directory, result_out = C:\Windows\system32 True 1
Fn
Module Load module_name = C:\Windows\system32\advapi32.dll, base_address = 0x75df0000 True 1
Fn
Module Get Address module_name = c:\windows\system32\advapi32.dll, function = DuplicateTokenEx, address_out = 0x75dfca24 True 1
Fn
COM Create interface = DC12A687-737F-11CF-884D-00AA004B2E24, cls_context = CLSCTX_INPROC_SERVER True 1
Fn
COM Create interface = 3BC15AF2-736C-477E-9E51-238AF8667DCC, cls_context = CLSCTX_INPROC_SERVER True 5
Fn
Module Get Address module_name = c:\windows\system32\ole32.dll, function = BindMoniker, address_out = 0x75c9c6a7 True 1
Fn
System Sleep duration = -1 (infinite) True 1
Fn
Thread 0x774
2 0
»
Category Operation Information Success Count Logfile
Window Create class_name = WSH-Timer, wndproc_parameter = 5710624 True 1
Fn
Window Set Attribute class_name = WSH-Timer, index = 18446744073709551595, new_long = 5710624 False 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image