IOC Report
Vqzx4PFehn.exe

loading gif

Files

File Path
Type
Category
Malicious
Vqzx4PFehn.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Program Files (x86)\Windows Defender\services.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files\Windows Security\BrowserCore\en-US\XXPWErhsUbDrk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Recovery\XXPWErhsUbDrk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\Default\Pictures\XXPWErhsUbDrk.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\28moAYly7n.bat
DOS batch file, ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\DtICHrzA.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\EqkKdrOv.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\SHKzphsQ.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\TQvqMYlM.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\VaRrMrQM.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\cvopZsny.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\fJkHwTWu.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\mqRpKNWg.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\nntxgNlb.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Users\user\Desktop\uCFUtfTN.log
PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Windows\Registration\csrss.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\portintosvc\driverInto.exe
PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
dropped
malicious
C:\Program Files (x86)\Windows Defender\c5b4cb5e9653cc
ASCII text, with very long lines (918), with no line terminators
dropped
C:\Program Files\Windows Security\BrowserCore\en-US\931b00cae9730a
ASCII text, with very long lines (865), with no line terminators
dropped
C:\ProgramData\Microsoft\Network\Downloader\qmgr.db
Extensible storage engine DataBase, version 0x620, checksum 0xf31f5ca1, page size 16384, DirtyShutdown, Windows version 10.0
dropped
C:\Recovery\931b00cae9730a
ASCII text, with very long lines (721), with no line terminators
dropped
C:\Users\Default\Pictures\931b00cae9730a
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\driverInto.exe.log
ASCII text, with CRLF line terminators
modified
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
data
modified
C:\Users\user\AppData\Local\Temp\0Iv3hBTsfc
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\0L4ikCTOAp
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\12amCzK2TW
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\13XpJa46MX
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\1HT2VriCdk
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\1XLlMziEAg
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\1hMfRAEMbM
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\2HAwxIgCir
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\2MBjDkjtnc
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\2jdfh5ZP1u
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\30dXVdli9U
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\3UJhkOZEjV
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\3mPgAbqAwM
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\44Fa4qmXwC
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\4JEijRsXB3
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\4JIBT30mvl
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\4dOB8oioHN
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\4lVFdTKR5c
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\4nwBgY6nYM
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\4pyo9obnQ2
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\4vUFNwDjB1
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\4xF0ndNYR1
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\5Mj2akZqlN
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\5aKVA6EUOv
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\5hZnllMgtr
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\5okqcWEmw1
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\65KytBYWtj
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\6Lp9iaSujL
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\6RlmaiBDJh
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\6zdPnU8B9w
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\73ZaSM0LDE
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\7DtyM9LoO2
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\7UdooU2JF5
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\7VU9H7YZKc
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\7ZM62vKokH
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\7pmvuRJSq8
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\7uPxAYqEJu
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\8RQK1aDBdJ
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\8bow8ajICu
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\90YnqVS141
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\96QA0sXOX6
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\97vG7ZJfCz
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\9R16GLpZcZ
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\AUXEQDby9B
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\AomSgvASrh
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\B4RFcMEvKM
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\B539ZCGK8a
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\B8GxsJrYqi
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\B8oPlr3jQ0
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\BBaiZ8qPDr
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\BHCsS4Tcvp
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\BWabNtZWRM
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\CAet0Eq64K
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\CXDve81O32
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\CdrHKSyFQn
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\CwsqLVdzqS
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\DCMHnLHIz7
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\DGEQpREgU2
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\DOZALIe7mA
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\DU9KqcY5Fg
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Da2cWNnVqm
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\DdCBjfyxuu
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\DqCkoxK5Am
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Dr8yn6v3tZ
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\DucsEtpniw
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Dx33uJYG2K
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\EG1oPNbosu
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\EIvU6qULDb
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\EdMYncgtcK
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\F7w3n3Nejz
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\FknuyWRhlQ
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\FmqJtWJ2ic
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\FuY6TZD3ta
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\G9R9ktbnjw
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\G9SVanmpLl
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\GSk6SFHuh6
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\GXIOu0pkah
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\GdB4o2Atya
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\GvDFbWFsu2
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\HKTtgvPX44
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\HoWVhfrbVY
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\I4rSQ4DoPl
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\ISOrmyDptN
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Ib8h7ix79z
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\IcadMWqGKZ
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\IusO6MGraR
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\JQEJPeElMm
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\JhZtTziwvM
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\JoNudZZwg5
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\KCrViFYARw
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\KsCIEWbBrN
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\LOVfrm6cVP
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\MhbfaL3iln
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\MjpcBfGcJw
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Mo7r8WhcEB
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\Mpqq6oFDmM
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\N0WMVuVbo5
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\NSFh5sh8Vv
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\NYVeaiGNzG
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\NZRwXJ5dMO
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\NZq6SPKjDB
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\OCImpRzZ7f
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\OCytboUdmn
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\OOGQXXx3RA
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\OyKGZtSDil
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\PUxbLkKTiu
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\PqmRM959jJ
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\PzXT2lkpI9
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\QLrqjHLCFn
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\QNiuGfe5Iu
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\QOSa21ACkN
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\R8UTTHYbqk
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\RGjzexYIco
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\RbAOIYL5eH
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\RjBMa5hhm0
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\S0E2EmvSXR
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Sk2S9rt9e7
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\SsZqQ2OnEY
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\Swtkpc9btI
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\TjW7zCrSIS
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\UWkqIDcAnU
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\UZPFVpoZMA
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\UoBgkd9SYI
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\UyUOTMz82p
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\VVgm5r8zzb
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\ViuX3uftX7
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\VmnB57YcQx
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\Vnl6vfjE2e
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\WOacyDnsS2
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\WPVBRw8B7g
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\WbE18eDCd9
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\WkVJ4gPCGf
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\WlSaeLSMyI
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\X6jyyRTISw
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\X8zy4QQrvy
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\X9AyFPTXPw
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\XFBJ4ivL6T
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\XH0l3EA6US
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\XHZm90MClc
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\XKPVUYFcy7
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\XSxd2wM0k4
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\Yf0uZIVP1h
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\YtnxI8eswZ
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\Z5gIYpTGhs
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\Z6bfFfN4nu
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\ZaT8ByDEyf
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\Zc9AoTGS4I
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\ZwNFIZT3HA
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_05ycp2n5.rqg.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_205xdwvr.taq.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_arzm4ooi.21l.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_bfi5dwaz.gl2.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_cijha0kx.mmy.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_edcbj1w1.1sy.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_fmfnaiyu.b5q.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_h4ujzb4i.yxw.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_hu444ybw.i5f.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ia3lhvh4.mqf.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_idad15rv.png.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_j4thqieb.qtr.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_jj1d1odw.isb.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_mgubltnd.5pu.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_nhw5lxbt.a1h.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ofvnwnkb.0f1.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ql4psgso.unb.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ry5injj0.4kv.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_skq3r2dh.lr4.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_suunzopm.snv.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_vfeggks5.nd3.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_xmxzq1xs.nwc.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_xwqonxtz.3bb.psm1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_yk1xckew.hm2.ps1
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\a7OlxXngyU
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\aatb8W3AVz
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\azQhB4PR3o
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\b7kPgNYFFk
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\bCCTvNkQTx
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\bbxmKKxpE2
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\c1Er4KmbKS
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\c58700x8F4
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\cBpcSD1VIf
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\chBRvlN2pN
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\cm36ikub3D
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\cpTnsZrZb1
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\dx8jlJEC0k
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\eCPcRVRxpJ
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\eNkwjJcxXw
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\eW6uZazJXy
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\ew9IvAgd6M
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\fdkcavdr7y
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\fnCwLCJQmV
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\gDT3vrmrV2
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\gTOsexUiK1
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\gXS2ycUMdm
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\hJYEefI0vU
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\hcJYj0mMmy
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\i6P9jd53Vj
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\iQZ54TbYWs
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\iXll3tAcUc
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\ioPbfUZlBC
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\j0BXfVZHuH
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\j5j4H0Ug7O
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\jJ2yvtGhoy
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\jKir4W2c7N
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\jTXpo6ufDg
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\jwFzc1Bwjm
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\k2kD7gtsCl
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\k98GPMvgV8
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\kMMy9bcjw2
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\lJ3sVUClNk
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\lTqbKB97Ii
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\lWx44ZM5Bo
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\lbde1gtHxg
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\liCbHlhSOV
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\ltBumxNsBh
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\m8KnMmm9M6
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\mKRzB2QGO2
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\mOVdiwrw9I
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\mcGwTmEnb0
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\mn2jOvyUyv
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\nBchxBpjRS
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\nMhddhVySr
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\njg8qaI6OB
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\oUfH6ofIBw
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\oX0RvzZesR
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\opGuncey9O
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\p3x7wGVtdl
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\pddCbAbcgv
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\q5NoW3a56g
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\qAX7Kl30dG
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\qBUZHMS0Vo
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\qL6QgquN2h
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\r3vpaV4K4x
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\rpYvoHRPWo
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\rq6afCwiN6
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\rw8CvTDhON
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\s5lJY8tuip
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\s8ypRMUDEE
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\sFuFcqA46P
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\sGU66Z6Jc7
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\sMGNeFd4yB
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\sQAH6P75qz
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\sYSYXONfMF
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\sqeB2XaEEC
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\srRj0cQb83
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\t5N6O4hJyy
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\tflKubiYtq
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\u6e6huj9TV
SQLite 3.x database, last written using SQLite version 3039003, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\uWX0IUVuCY
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\uvicgdzsD2
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\v7pR7utqBS
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\vGHHsj80cA
SQLite 3.x database, last written using SQLite version 3042000, file counter 11, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 11
dropped
C:\Users\user\AppData\Local\Temp\vpLwj6wZQE
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\wVvAAMGt7r
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\x7EkTf9NEX
SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\x9fbOMJRuq
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\xM1Nd8MkBx
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\xXDO915h2n
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\xfipqq1p8e
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\yGiVj0kfUW
SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 3
dropped
C:\Windows\Registration\886983d96e3d3e
ASCII text, with very long lines (376), with no line terminators
dropped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
JSON data
dropped
C:\portintosvc\11aaa3d75384f9
ASCII text, with very long lines (918), with no line terminators
dropped
C:\portintosvc\6iyrEfS0qZMUeKUvqyCENK8F6bD2a9LOXf0Mm.bat
ASCII text, with CRLF line terminators
dropped
C:\portintosvc\X5ZTZfC.vbe
data
dropped
\Device\Null
ASCII text, with CRLF line terminators
dropped
There are 281 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\Vqzx4PFehn.exe
"C:\Users\user\Desktop\Vqzx4PFehn.exe"
malicious
C:\Windows\SysWOW64\wscript.exe
"C:\Windows\System32\WScript.exe" "C:\portintosvc\X5ZTZfC.vbe"
malicious
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\cmd.exe /c ""C:\portintosvc\6iyrEfS0qZMUeKUvqyCENK8F6bD2a9LOXf0Mm.bat" "
malicious
C:\portintosvc\driverInto.exe
"C:\portintosvc/driverInto.exe"
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\Recovery\XXPWErhsUbDrk.exe'
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\Program Files\Windows Security\BrowserCore\en-US\XXPWErhsUbDrk.exe'
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\Users\Default User\My Documents\My Pictures\XXPWErhsUbDrk.exe'
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\Program Files (x86)\windows defender\services.exe'
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\Windows\Registration\csrss.exe'
malicious
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
"powershell" -Command Add-MpPreference -ExclusionPath 'C:\portintosvc\driverInto.exe'
malicious
C:\Windows\System32\cmd.exe
"C:\Windows\System32\cmd.exe" /C "C:\Users\user\AppData\Local\Temp\28moAYly7n.bat"
malicious
C:\Windows\System32\PING.EXE
ping -n 10 localhost
malicious
C:\Users\Default\Pictures\XXPWErhsUbDrk.exe
"C:\Users\Default User\My Documents\My Pictures\XXPWErhsUbDrk.exe"
malicious
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Windows\System32\chcp.com
chcp 65001
C:\Windows\System32\wbem\WmiPrvSE.exe
C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
There are 14 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://intopart.top/Eternalpollgeocpu.php
172.67.144.153
malicious
http://pesterbdd.com/images/Pester.png
unknown
malicious
https://api.telegram.org/bot7126538506:AAGUzEDEgn6X6JiRyzOOTz-UryNJDm6IzOs/sendPhoto
149.154.167.220
https://duckduckgo.com/chrome_newtab
unknown
http://nuget.org/NuGet.exe
unknown
https://duckduckgo.com/ac/?q=
unknown
https://api.telegram.org
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
https://api.telegram.org/bot
unknown
http://schemas.xmlsoap.org/soap/encoding/
unknown
http://www.apache.org/licenses/LICENSE-2.0.html
unknown
http://ipinfo.io
unknown
https://contoso.com/License
unknown
https://contoso.com/Icon
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://g.live.com/odclientsettings/ProdV2.C:
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
https://api.telegram.org/bot7126538506:AAGUzEDEgn6X6JiRyzOOTz-UryNJDm6IzOs/sendPhotoX
unknown
https://www.ecosia.org/newtab/
unknown
https://github.com/Pester/Pester
unknown
https://ipinfo.io
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://g.live.com/odclientsettings/Prod.C:
unknown
https://ipinfo.io/country
34.117.186.192
https://g.live.com/odclientsettings/ProdV2
unknown
https://g.live.com/odclientsettings/ProdV2?OneDriveUpdate=f359a5df14f97b6802371976c96
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
http://schemas.xmlsoap.org/wsdl/
unknown
https://contoso.com/
unknown
https://nuget.org/nuget.exe
unknown
https://aka.ms/pscore68
unknown
http://api.telegram.org
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
https://g.live.com/1rewlive5skydrive/OneDriveProductionV2?OneDriveUpdate=9c123752e31a927b78dc96231b6
unknown
https://ipinfo.io/ip
34.117.186.192
There are 26 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
intopart.top
172.67.144.153
malicious
ipinfo.io
34.117.186.192
api.telegram.org
149.154.167.220

IPs

IP
Domain
Country
Malicious
172.67.144.153
intopart.top
United States
malicious
34.117.186.192
ipinfo.io
United States
149.154.167.220
api.telegram.org
United Kingdom
127.0.0.1
unknown
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
LangID
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\WScript.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\WScript.exe.ApplicationCompany
HKEY_CURRENT_USER\SOFTWARE\4a9edd4655d4bf910b3e73b621feb6687e6aa4a2
4adf9bbb6a1e5fc325cfad0f66ae961c9fd5400d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\driverInto_RASMANCS
FileDirectory
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\cmd.exe.FriendlyAppName
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\cmd.exe.ApplicationCompany
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASAPI32
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
EnableFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
EnableAutoFileTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
EnableConsoleTracing
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
FileTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
ConsoleTracingMask
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
MaxFileSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\XXPWErhsUbDrk_RASMANCS
FileDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
PerfMMFileName
There are 25 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
AC2000
unkown
page readonly
malicious
6DE3000
heap
page read and write
malicious
13164000
trusted library allocation
page read and write
malicious
EF245FE000
stack
page read and write
1555349C000
trusted library allocation
page read and write
6C3E5BE000
stack
page read and write
1C7E0000
trusted library allocation
page read and write
36EB000
trusted library allocation
page read and write
74F1000
heap
page read and write
94D8F6C000
stack
page read and write
22ECE694000
heap
page read and write
1C2BA902000
trusted library allocation
page read and write
22ECF5D4000
trusted library allocation
page read and write
985000
heap
page read and write
22ECFDA4000
trusted library allocation
page read and write
2F49000
trusted library allocation
page read and write
7FFD9BC00000
trusted library allocation
page read and write
2A73632B000
trusted library allocation
page read and write
12B0000
trusted library allocation
page read and write
22ECF5E8000
trusted library allocation
page read and write
1BC84000
unkown
page readonly
2615C482000
heap
page read and write
9883273000
stack
page read and write
22ECE680000
heap
page execute and read and write
50FE000
stack
page read and write
37C3000
trusted library allocation
page read and write
1045000
unkown
page read and write
1C2C940B000
trusted library allocation
page read and write
1270000
heap
page read and write
6C3F30E000
stack
page read and write
1C2BA9A8000
trusted library allocation
page read and write
EF24AFD000
stack
page read and write
327C000
heap
page read and write
26435CD0000
heap
page read and write
1CD902FB000
trusted library allocation
page read and write
C4A75EE000
stack
page read and write
2615E411000
trusted library allocation
page read and write
2A732864000
heap
page read and write
C4A75AF000
unkown
page read and write
15553474000
trusted library allocation
page read and write
1CDE7C98000
heap
page read and write
F6A07FF000
unkown
page read and write
AC2000
unkown
page readonly
1D30C000
stack
page read and write
5A2F000
stack
page read and write
54625CE000
stack
page read and write
2596C384000
heap
page read and write
1D6BE000
stack
page read and write
7FFD9B9A4000
trusted library allocation
page read and write
1033000
unkown
page readonly
2A734551000
trusted library allocation
page read and write
73CF000
heap
page read and write
1B88F000
heap
page read and write
EF24B78000
stack
page read and write
B10000
heap
page read and write
32CD000
heap
page read and write
22ECF74D000
trusted library allocation
page read and write
1BB4F000
stack
page read and write
7FFD9B9A0000
trusted library allocation
page read and write
7523000
heap
page read and write
1555354A000
trusted library allocation
page read and write
2615C754000
heap
page read and write
EF2594E000
stack
page read and write
7FFD9B9BD000
trusted library allocation
page execute and read and write
20A61840000
heap
page read and write
1B8F4000
heap
page read and write
32CA000
heap
page read and write
26160236000
trusted library allocation
page read and write
1C2C91B1000
trusted library allocation
page read and write
54615F9000
stack
page read and write
1C2B9D68000
trusted library allocation
page read and write
2F41000
trusted library allocation
page read and write
1B933000
heap
page execute and read and write
2A7327B0000
trusted library allocation
page read and write
15553431000
trusted library allocation
page read and write
32CD000
heap
page read and write
2615FC9E000
trusted library allocation
page read and write
90F3DFC000
stack
page read and write
2A744571000
trusted library allocation
page read and write
7485000
heap
page read and write
1BC50000
unkown
page readonly
20A614F0000
heap
page read and write
2615C6B0000
trusted library allocation
page read and write
1C350000
heap
page read and write
1064000
unkown
page readonly
2A736375000
trusted library allocation
page read and write
22ECFBBA000
trusted library allocation
page read and write
1BC4E000
stack
page read and write
1CD9030B000
trusted library allocation
page read and write
1C58F000
stack
page read and write
2616E411000
trusted library allocation
page read and write
1BA4F000
stack
page read and write
7FFD9BA86000
trusted library allocation
page execute and read and write
2615C49B000
heap
page read and write
1CD81869000
trusted library allocation
page read and write
A75000
heap
page read and write
5461AFC000
stack
page read and write
1CD8188F000
trusted library allocation
page read and write
90F367E000
unkown
page read and write
36F3000
trusted library allocation
page read and write
6C3E439000
stack
page read and write
2596C044000
heap
page read and write
20A73344000
trusted library allocation
page read and write
2615C750000
heap
page read and write
A8A000
heap
page read and write
54619FE000
stack
page read and write
3261000
heap
page read and write
32CA000
heap
page read and write
C4A7D7E000
stack
page read and write
2EC0000
heap
page read and write
7523000
heap
page read and write
988397C000
stack
page read and write
2A73288A000
heap
page read and write
1C2C931D000
trusted library allocation
page read and write
1CD80C04000
trusted library allocation
page read and write
1CDE7D83000
heap
page read and write
1CD80A51000
trusted library allocation
page read and write
1063000
unkown
page readonly
1CD90244000
trusted library allocation
page read and write
22ECCB50000
heap
page read and write
1C2B9BD2000
trusted library allocation
page read and write
1C2B9207000
trusted library allocation
page read and write
5B6D000
stack
page read and write
15553486000
trusted library allocation
page read and write
B11000
heap
page read and write
2615C630000
trusted library section
page read and write
6C3E27D000
stack
page read and write
32A0000
heap
page read and write
20A613F0000
heap
page read and write
1BC68000
unkown
page readonly
98833FE000
stack
page read and write
F6A08FF000
stack
page read and write
6C3DD4F000
unkown
page read and write
2615F4CD000
trusted library allocation
page read and write
EF24D7E000
stack
page read and write
7FFD9B9C4000
trusted library allocation
page read and write
20A73341000
trusted library allocation
page read and write
2A7355E0000
trusted library allocation
page read and write
6C3DCC3000
stack
page read and write
73F1000
heap
page read and write
6F82000
heap
page read and write
329E000
heap
page read and write
103E000
unkown
page read and write
2BFD000
stack
page read and write
22ECCC28000
heap
page read and write
98837FA000
stack
page read and write
C4A7AFE000
stack
page read and write
2615E638000
trusted library allocation
page read and write
1C24D000
stack
page read and write
22ECEA9B000
trusted library allocation
page read and write
73F2000
heap
page read and write
50BD000
stack
page read and write
1555349F000
trusted library allocation
page read and write
1CDE9670000
trusted library allocation
page read and write
2615C518000
heap
page read and write
2616E484000
trusted library allocation
page read and write
5F0000
heap
page read and write
1000000
unkown
page readonly
1CD804CD000
trusted library allocation
page read and write
2A73566F000
trusted library allocation
page read and write
1C2C9560000
trusted library allocation
page read and write
2A734FA2000
trusted library allocation
page read and write
1C2BA356000
trusted library allocation
page read and write
2615C430000
trusted library section
page read and write
1CD81951000
trusted library allocation
page read and write
1052000
heap
page read and write
2A7352C3000
trusted library allocation
page read and write
20A64613000
trusted library allocation
page read and write
A8E000
heap
page read and write
1C2C9367000
trusted library allocation
page read and write
AC0000
unkown
page readonly
1C7DD000
stack
page read and write
2A7445C3000
trusted library allocation
page read and write
B07000
unkown
page readonly
36E3000
trusted library allocation
page read and write
6C3E4B8000
stack
page read and write
22ECCCA8000
heap
page read and write
ADB000
heap
page read and write
13286000
trusted library allocation
page read and write
AD6000
heap
page read and write
1C2B7130000
heap
page read and write
20A643CD000
trusted library allocation
page read and write
12E0000
heap
page execute and read and write
7423000
heap
page read and write
568E000
stack
page read and write
15553448000
trusted library allocation
page read and write
22ECFBF3000
trusted library allocation
page read and write
592E000
stack
page read and write
1CD902EC000
trusted library allocation
page read and write
3077000
trusted library allocation
page read and write
90F3AF9000
stack
page read and write
546264E000
stack
page read and write
AC0000
heap
page read and write
1C2BAACF000
trusted library allocation
page read and write
2596C045000
heap
page read and write
6470000
trusted library allocation
page read and write
20A6442F000
trusted library allocation
page read and write
20A61570000
trusted library allocation
page read and write
6460000
heap
page read and write
2A732620000
heap
page read and write
EF25ACC000
stack
page read and write
22ED0208000
trusted library allocation
page read and write
1C2B716B000
heap
page read and write
3289000
heap
page read and write
EF24533000
stack
page read and write
32AD000
heap
page read and write
328E000
heap
page read and write
C4A8B4C000
stack
page read and write
2A7327F0000
heap
page read and write
1B912000
unkown
page readonly
EF24BF7000
stack
page read and write
7FFD9B9CD000
trusted library allocation
page execute and read and write
2596C02F000
heap
page read and write
2A73513B000
trusted library allocation
page read and write
98845CC000
stack
page read and write
1C800000
heap
page read and write
C4A7E7C000
stack
page read and write
1C2B70B0000
heap
page read and write
6C3E1FB000
stack
page read and write
20A61530000
heap
page read and write
7FFD9BE8C000
trusted library allocation
page read and write
37D7000
trusted library allocation
page read and write
EF24CFA000
stack
page read and write
37AA000
trusted library allocation
page read and write
7FFD9BF30000
trusted library allocation
page read and write
32BC000
heap
page read and write
1C2BAF5C000
trusted library allocation
page read and write
8F2000
stack
page read and write
301E000
stack
page read and write
1CD810BD000
trusted library allocation
page read and write
C4A7C7A000
stack
page read and write
26435F00000
heap
page read and write
1035000
heap
page read and write
2EF0000
heap
page execute and read and write
1C2B964D000
trusted library allocation
page read and write
1C2BA2A0000
trusted library allocation
page read and write
5461BFB000
stack
page read and write
1CD80F9B000
trusted library allocation
page read and write
22ECCA50000
heap
page read and write
20A62F30000
trusted library allocation
page read and write
1CD80228000
trusted library allocation
page read and write
B27000
heap
page read and write
A7D000
heap
page read and write
4CA1000
heap
page read and write
20A6446A000
trusted library allocation
page read and write
2615F4A1000
trusted library allocation
page read and write
74B9000
heap
page read and write
2A73557D000
trusted library allocation
page read and write
15553430000
trusted library allocation
page read and write
1062000
unkown
page read and write
2A734080000
heap
page readonly
7FFD9BE90000
trusted library allocation
page read and write
1CDE7CD4000
heap
page read and write
2A734204000
heap
page read and write
7FFD9BC10000
trusted library allocation
page read and write
5A6B000
stack
page read and write
1CDE9580000
heap
page read and write
15553580000
trusted library allocation
page read and write
22ECE9F5000
trusted library allocation
page read and write
22ECE560000
heap
page read and write
2A7340A0000
trusted library allocation
page read and write
20A615CB000
heap
page read and write
20A6408B000
trusted library allocation
page read and write
7FFD9BEA0000
trusted library allocation
page read and write
31C0000
heap
page read and write
C4A8A47000
stack
page read and write
20A61870000
heap
page read and write
2A73560C000
trusted library allocation
page read and write
22ECCCA3000
heap
page read and write
26435D50000
heap
page read and write
1C2B717A000
heap
page read and write
20A65111000
trusted library allocation
page read and write
C4A8BCE000
stack
page read and write
546177E000
stack
page read and write
1BF4E000
stack
page read and write
6C3E73B000
stack
page read and write
B27000
heap
page read and write
328A000
heap
page read and write
37AC000
trusted library allocation
page read and write
1C2C9473000
trusted library allocation
page read and write
7FFD9BA5C000
trusted library allocation
page execute and read and write
155535D0000
remote allocation
page read and write
15553430000
trusted library allocation
page read and write
1CDE7D19000
heap
page read and write
6C3F28C000
stack
page read and write
20A642EC000
trusted library allocation
page read and write
B13000
heap
page read and write
9882FDE000
stack
page read and write
2615C3F0000
heap
page read and write
103D000
heap
page read and write
1210000
heap
page read and write
2B4B000
stack
page read and write
12F0000
heap
page read and write
1CD90073000
trusted library allocation
page read and write
EF245BE000
unkown
page read and write
3267000
heap
page read and write
1AF70000
trusted library allocation
page read and write
12F4000
heap
page read and write
2596C045000
heap
page read and write
1555343E000
trusted library allocation
page read and write
22ECF5E0000
trusted library allocation
page read and write
1CDE7CD0000
heap
page read and write
1CD81304000
trusted library allocation
page read and write
32A8000
heap
page read and write
22ECF9E3000
trusted library allocation
page read and write
ABD000
heap
page read and write
20A637DC000
trusted library allocation
page read and write
2615C3C0000
heap
page read and write
1CDE9710000
heap
page read and write
7FFD9BBB0000
trusted library allocation
page read and write
26435D58000
heap
page read and write
20A646CE000
trusted library allocation
page read and write
7FFD9BCD0000
trusted library allocation
page read and write
22ECFCE8000
trusted library allocation
page read and write
988464C000
stack
page read and write
1C2C9433000
trusted library allocation
page read and write
2F10000
unkown
page readonly
9883579000
stack
page read and write
11F0000
heap
page read and write
2596C033000
heap
page read and write
9CE000
stack
page read and write
20A645B2000
trusted library allocation
page read and write
15553438000
trusted library allocation
page read and write
7FFD9BB60000
trusted library allocation
page read and write
12F41000
trusted library allocation
page read and write
2596C110000
heap
page read and write
90F3393000
stack
page read and write
20A63D62000
trusted library allocation
page read and write
1C2C95CD000
trusted library allocation
page read and write
20A64311000
trusted library allocation
page read and write
54626C7000
stack
page read and write
1C2C9468000
trusted library allocation
page read and write
2A73281F000
heap
page read and write
22ECEEAC000
trusted library allocation
page read and write
2A734200000
heap
page read and write
7FFD9BF40000
trusted library allocation
page read and write
FE0000
heap
page read and write
2A7357F2000
trusted library allocation
page read and write
1C2C937F000
trusted library allocation
page read and write
1CDE95E0000
trusted library allocation
page read and write
1CD90031000
trusted library allocation
page read and write
74F2000
heap
page read and write
90F3CFC000
stack
page read and write
1C2BAA0E000
trusted library allocation
page read and write
4C90000
heap
page read and write
1555352F000
trusted library allocation
page read and write
2615C4C8000
heap
page read and write
2615C448000
heap
page read and write
1C2B717C000
heap
page read and write
20A650EC000
trusted library allocation
page read and write
1BC70000
unkown
page readonly
31C9000
heap
page read and write
7390000
heap
page read and write
7FFD9BEB0000
trusted library allocation
page execute and read and write
1CD90001000
trusted library allocation
page read and write
1C2B718C000
heap
page read and write
22ECCB30000
heap
page read and write
20A6421A000
trusted library allocation
page read and write
328B000
heap
page read and write
4C5E000
stack
page read and write
2615C610000
heap
page read and write
7FFD9B9FC000
trusted library allocation
page execute and read and write
22ECE690000
heap
page read and write
1CD8120F000
trusted library allocation
page read and write
1C2B7172000
heap
page read and write
1CDE9600000
trusted library allocation
page read and write
8D8000
stack
page read and write
1274000
heap
page read and write
1C2C94C0000
trusted library allocation
page read and write
2A732720000
heap
page read and write
1C2B9F41000
trusted library allocation
page read and write
5461A7F000
stack
page read and write
155534F2000
trusted library allocation
page read and write
1C2B7350000
trusted library allocation
page read and write
2596C210000
heap
page read and write
20A65131000
trusted library allocation
page read and write
127E000
heap
page read and write
1C373000
heap
page read and write
90F3B79000
stack
page read and write
22ED0162000
trusted library allocation
page read and write
15553518000
trusted library allocation
page read and write
2A735149000
trusted library allocation
page read and write
2615F411000
trusted library allocation
page read and write
1CD8102E000
trusted library allocation
page read and write
2A736370000
trusted library allocation
page read and write
2615FC38000
trusted library allocation
page read and write
2615F713000
trusted library allocation
page read and write
1D50C000
stack
page read and write
2615FC77000
trusted library allocation
page read and write
73C0000
heap
page read and write
32CA000
heap
page read and write
15553521000
trusted library allocation
page read and write
132E3000
trusted library allocation
page read and write
90F33DE000
stack
page read and write
EF248FE000
stack
page read and write
2615C48A000
heap
page read and write
2A732780000
heap
page read and write
ACD000
heap
page read and write
13155000
trusted library allocation
page read and write
2596C304000
heap
page read and write
1033000
unkown
page readonly
90F3BFE000
stack
page read and write
20A644E6000
trusted library allocation
page read and write
20A64082000
trusted library allocation
page read and write
1C2BA211000
trusted library allocation
page read and write
22ECCBB0000
trusted library section
page read and write
101C000
heap
page read and write
EF25A4C000
stack
page read and write
15553524000
trusted library allocation
page read and write
546284E000
stack
page read and write
15FE000
stack
page read and write
98832FE000
unkown
page read and write
8FA000
stack
page read and write
A50000
heap
page read and write
2615C440000
heap
page read and write
3699000
trusted library allocation
page read and write
1554E71A000
heap
page read and write
90F37F9000
stack
page read and write
9883A7B000
stack
page read and write
646F000
heap
page read and write
3708000
trusted library allocation
page read and write
22ECCC7B000
heap
page read and write
1CD813C0000
trusted library allocation
page read and write
6E6E000
stack
page read and write
3260000
heap
page read and write
94E000
stack
page read and write
2F12000
unkown
page readonly
2A735853000
trusted library allocation
page read and write
7453000
heap
page read and write
132AE000
trusted library allocation
page read and write
1CD812A2000
trusted library allocation
page read and write
343E000
stack
page read and write
FC1000
trusted library allocation
page read and write
1C2C91CC000
trusted library allocation
page read and write
2A7327D0000
trusted library allocation
page read and write
73F1000
heap
page read and write
3291000
heap
page read and write
1CDE7DB0000
heap
page read and write
20A61590000
heap
page read and write
C4A894E000
stack
page read and write
13022000
trusted library allocation
page read and write
1C2C946C000
trusted library allocation
page read and write
20A63311000
trusted library allocation
page read and write
EF24E7C000
stack
page read and write
2E9E000
stack
page read and write
6D7C000
heap
page read and write
1B855000
heap
page read and write
2615C4C5000
heap
page read and write
988387E000
stack
page read and write
1C2B8F90000
heap
page execute and read and write
471E000
stack
page read and write
14FE000
stack
page read and write
7FFD9BBA0000
trusted library allocation
page read and write
20A615D8000
heap
page read and write
51E0000
heap
page read and write
7491000
heap
page read and write
37D2000
trusted library allocation
page read and write
546157E000
stack
page read and write
2615C484000
heap
page read and write
EF24A7B000
stack
page read and write
7522000
heap
page read and write
1555352C000
trusted library allocation
page read and write
7FFD9BE50000
trusted library allocation
page read and write
1D710000
heap
page read and write
1CDE7CCB000
heap
page read and write
2A734090000
heap
page execute and read and write
1C2BA422000
trusted library allocation
page read and write
B02000
unkown
page readonly
EF24979000
stack
page read and write
7FFD9BB40000
trusted library allocation
page read and write
98835FD000
stack
page read and write
1D721000
heap
page read and write
90F39F9000
stack
page read and write
22ECE575000
heap
page read and write
7FFD9BA50000
trusted library allocation
page read and write
1CDE7D16000
heap
page read and write
7FFD9BE30000
trusted library allocation
page read and write
22ECFC87000
trusted library allocation
page read and write
107E000
heap
page read and write
32A0000
heap
page read and write
1C2B9EED000
trusted library allocation
page read and write
90F36FF000
stack
page read and write
20A64B9E000
trusted library allocation
page read and write
7422000
heap
page read and write
1C2C9181000
trusted library allocation
page read and write
2615E0C4000
heap
page read and write
22ECCC20000
heap
page read and write
22ECEC08000
trusted library allocation
page read and write
15553537000
trusted library allocation
page read and write
2596C045000
heap
page read and write
6C70000
heap
page read and write
7454000
heap
page read and write
155534EA000
trusted library allocation
page read and write
1CD81E02000
trusted library allocation
page read and write
AC0000
heap
page read and write
1CDE95C0000
trusted library allocation
page read and write
74C1000
heap
page read and write
20A614D0000
heap
page read and write
20A62FC0000
heap
page read and write
20A65136000
trusted library allocation
page read and write
6C3E63C000
stack
page read and write
2A734100000
heap
page read and write
90F48CD000
stack
page read and write
1555347D000
trusted library allocation
page read and write
32F5000
heap
page read and write
2596C033000
heap
page read and write
2596C033000
heap
page read and write
2596C380000
heap
page read and write
C4A78FE000
stack
page read and write
15553445000
trusted library allocation
page read and write
1AF40000
trusted library allocation
page read and write
20A61850000
trusted library allocation
page read and write
2A734110000
trusted library allocation
page read and write
22ECCC5D000
heap
page read and write
54618FD000
stack
page read and write
22ED026E000
trusted library allocation
page read and write
90F397D000
stack
page read and write
8CE000
stack
page read and write
7FFD9BBE0000
trusted library allocation
page execute and read and write
90F4849000
stack
page read and write
AE4000
heap
page read and write
900000
heap
page readonly
6C3E2F9000
stack
page read and write
13159000
trusted library allocation
page read and write
3286000
heap
page read and write
1054000
heap
page read and write
2615E020000
heap
page execute and read and write
B1E000
heap
page read and write
22ED032F000
trusted library allocation
page read and write
3285000
heap
page read and write
32BC000
heap
page read and write
7485000
heap
page read and write
155534D3000
trusted library allocation
page read and write
1063000
unkown
page write copy
3290000
heap
page read and write
73C1000
heap
page read and write
4C90000
heap
page read and write
1C2B7104000
heap
page read and write
1C34E000
stack
page read and write
1CD80DAF000
trusted library allocation
page read and write
988444E000
stack
page read and write
20A63F0C000
trusted library allocation
page read and write
EF2487F000
stack
page read and write
6D70000
heap
page read and write
22ECCBC0000
trusted library section
page read and write
90F38F7000
stack
page read and write
DBE000
stack
page read and write
7FFD9BF50000
trusted library allocation
page execute and read and write
2615C4C3000
heap
page read and write
20A64A93000
trusted library allocation
page read and write
578F000
stack
page read and write
7FFD9BCC2000
trusted library allocation
page read and write
13FF000
stack
page read and write
9883679000
stack
page read and write
20A64647000
trusted library allocation
page read and write
1C2B7080000
heap
page read and write
2615C47B000
heap
page read and write
1C2C9479000
trusted library allocation
page read and write
1CDE7CD2000
heap
page read and write
20A615D6000
heap
page read and write
7FFD9B9C0000
trusted library allocation
page read and write
98846CE000
stack
page read and write
2A7345D6000
trusted library allocation
page read and write
36CF000
trusted library allocation
page read and write
2A732825000
heap
page read and write
1CDE7D6B000
heap
page read and write
1BC52000
unkown
page readonly
7FFD9BBC2000
trusted library allocation
page read and write
2615F188000
trusted library allocation
page read and write
9883479000
stack
page read and write
73D2000
heap
page read and write
2596C046000
heap
page read and write
8EB000
stack
page read and write
32BC000
heap
page read and write
1C2B9D86000
trusted library allocation
page read and write
B10000
heap
page read and write
2A73590E000
trusted library allocation
page read and write
90F3A77000
stack
page read and write
54614FF000
stack
page read and write
20A61617000
heap
page read and write
20A62FC4000
heap
page read and write
EF25B4E000
stack
page read and write
C4A7DFE000
stack
page read and write
554E000
stack
page read and write
1CD813B7000
trusted library allocation
page read and write
26160231000
trusted library allocation
page read and write
98839FF000
stack
page read and write
2A735DB7000
trusted library allocation
page read and write
C4A8ACD000
stack
page read and write
2A734A1C000
trusted library allocation
page read and write
22ECE9E1000
trusted library allocation
page read and write
54627CC000
stack
page read and write
1CDE7D8A000
heap
page read and write
1C2B7110000
heap
page read and write
1C2B73D4000
heap
page read and write
155535D0000
remote allocation
page read and write
20A64C01000
trusted library allocation
page read and write
54611CE000
stack
page read and write
EF249FF000
stack
page read and write
22ECFA9E000
trusted library allocation
page read and write
B11000
heap
page read and write
1CD80001000
trusted library allocation
page read and write
7FFD9BE80000
trusted library allocation
page read and write
1B8F8000
heap
page read and write
2615E8DC000
trusted library allocation
page read and write
1C2B7138000
heap
page read and write
B11000
heap
page read and write
1084000
heap
page read and write
3283000
heap
page read and write
3040000
heap
page read and write
2615F56A000
trusted library allocation
page read and write
1C2C9603000
trusted library allocation
page read and write
7FFD9B9B8000
trusted library allocation
page read and write
26435F04000
heap
page read and write
1C2BA1AD000
trusted library allocation
page read and write
54617F9000
stack
page read and write
2615C670000
heap
page readonly
1B884000
heap
page read and write
20A615D4000
heap
page read and write
2F30000
heap
page read and write
22ECCBE4000
heap
page read and write
2615F43D000
trusted library allocation
page read and write
73F1000
heap
page read and write
1CD81784000
trusted library allocation
page read and write
3296000
heap
page read and write
1C2B7340000
heap
page readonly
4CA0000
trusted library allocation
page read and write
53CF000
stack
page read and write
2A7354EE000
trusted library allocation
page read and write
6C3F187000
stack
page read and write
6464000
heap
page read and write
20A63F44000
trusted library allocation
page read and write
378D000
trusted library allocation
page read and write
B12000
heap
page read and write
ACD000
heap
page read and write
4B64000
heap
page read and write
1C2C9471000
trusted library allocation
page read and write
1C04E000
stack
page read and write
1CDE7DA0000
heap
page read and write
1CD81DDD000
trusted library allocation
page read and write
5461183000
stack
page read and write
A8A000
heap
page read and write
74C0000
heap
page read and write
9DB000
heap
page read and write
AC8000
heap
page read and write
3292000
heap
page read and write
32CA000
heap
page read and write
1D95A000
stack
page read and write
2EFB000
stack
page read and write
7FFD9B9B3000
trusted library allocation
page read and write
1B940000
heap
page read and write
706D000
stack
page read and write
32CA000
heap
page read and write
2A732803000
heap
page read and write
155534C1000
trusted library allocation
page read and write
A79000
heap
page read and write
B11000
heap
page read and write
8DC000
stack
page read and write
74B9000
heap
page read and write
2596C045000
heap
page read and write
155535D0000
remote allocation
page read and write
22ECCC61000
heap
page read and write
7FFD9BA56000
trusted library allocation
page read and write
3294000
heap
page read and write
2615E080000
heap
page execute and read and write
5461877000
stack
page read and write
2615FD5F000
trusted library allocation
page read and write
8E5000
stack
page read and write
1C2B73D0000
heap
page read and write
1C2B7330000
trusted library allocation
page read and write
2616E441000
trusted library allocation
page read and write
EF259C7000
stack
page read and write
1C2B8F27000
heap
page execute and read and write
1B810000
heap
page read and write
6C3E0F9000
stack
page read and write
2596C1F0000
heap
page read and write
32AE000
heap
page read and write
1554E71A000
heap
page read and write
1290000
trusted library allocation
page read and write
7523000
heap
page read and write
2A73281B000
heap
page read and write
2596C00B000
heap
page read and write
2A732700000
heap
page read and write
3240000
heap
page read and write
329D000
heap
page read and write
2A735DDE000
trusted library allocation
page read and write
1C2B9181000
trusted library allocation
page read and write
1C2C91A1000
trusted library allocation
page read and write
1C2B9170000
heap
page execute and read and write
1BC72000
unkown
page readonly
2615F52F000
trusted library allocation
page read and write
1080000
heap
page read and write
507E000
stack
page read and write
15553494000
trusted library allocation
page read and write
20A615EB000
heap
page read and write
1001000
unkown
page execute read
8E9000
stack
page read and write
6F6F000
stack
page read and write
1C2B7090000
heap
page read and write
1C2C948B000
trusted library allocation
page read and write
22ECCC3E000
heap
page read and write
37DE000
trusted library allocation
page read and write
1CD902F3000
trusted library allocation
page read and write
20A61598000
heap
page read and write
22ED0247000
trusted library allocation
page read and write
1B930000
heap
page execute and read and write
1B4CB000
stack
page read and write
2615F4CF000
trusted library allocation
page read and write
2615C730000
heap
page read and write
A79000
heap
page read and write
31F0000
heap
page read and write
546147F000
unkown
page read and write
1050000
heap
page read and write
3281000
heap
page read and write
90F49CE000
stack
page read and write
AC0000
unkown
page readonly
7FFD9BBF0000
trusted library allocation
page read and write
3280000
heap
page read and write
C9A000
unkown
page readonly
2F20000
unkown
page readonly
1B910000
unkown
page readonly
1C2B7310000
trusted library allocation
page read and write
32BC000
heap
page read and write
A58000
heap
page read and write
32A2000
heap
page read and write
A7E000
heap
page read and write
2A7328BB000
heap
page read and write
6C3DDCF000
stack
page read and write
22ECFB04000
trusted library allocation
page read and write
1CDE7D77000
heap
page read and write
20A63396000
trusted library allocation
page read and write
90F387F000
stack
page read and write
2615EE62000
trusted library allocation
page read and write
B27000
heap
page read and write
2615E087000
heap
page execute and read and write
1CD81120000
trusted library allocation
page read and write
A8A000
heap
page read and write
98834FF000
stack
page read and write
AC8000
heap
page read and write
103E000
unkown
page write copy
6DD9000
heap
page read and write
7FFD9B9AD000
trusted library allocation
page execute and read and write
32CD000
heap
page read and write
1C2B93A8000
trusted library allocation
page read and write
1CDE7C70000
heap
page read and write
22ECCC00000
trusted library allocation
page read and write
4F7E000
stack
page read and write
2615C6F0000
trusted library allocation
page read and write
1C2B8FC2000
heap
page read and write
20A73311000
trusted library allocation
page read and write
564E000
stack
page read and write
98838FE000
stack
page read and write
36AD000
trusted library allocation
page read and write
1C2BA2DF000
trusted library allocation
page read and write
F6A06FB000
stack
page read and write
20A62F00000
trusted library allocation
page read and write
2A735E9F000
trusted library allocation
page read and write
54616FB000
stack
page read and write
9884546000
stack
page read and write
2A744581000
trusted library allocation
page read and write
1000000
unkown
page readonly
AA7000
heap
page read and write
980000
heap
page read and write
2596C310000
heap
page read and write
20A61874000
heap
page read and write
7FFD9BBC0000
trusted library allocation
page read and write
1C394000
heap
page read and write
1555330A000
heap
page read and write
2FD0000
heap
page read and write
A7F000
heap
page read and write
6C3E33E000
stack
page read and write
3749000
trusted library allocation
page read and write
1B86B000
heap
page read and write
20A64B78000
trusted library allocation
page read and write
32A7000
heap
page read and write
B32000
heap
page read and write
2A734140000
trusted library allocation
page read and write
C4A79FE000
stack
page read and write
AA0000
heap
page read and write
1C2BAF81000
trusted library allocation
page read and write
20A63538000
trusted library allocation
page read and write
C4A7979000
stack
page read and write
1DA5C000
stack
page read and write
7395000
heap
page read and write
2BB0000
heap
page read and write
73F1000
heap
page read and write
90F3C7E000
stack
page read and write
1110000
heap
page read and write
2A735725000
trusted library allocation
page read and write
2615C3D0000
heap
page read and write
2A736350000
trusted library allocation
page read and write
546167E000
stack
page read and write
1C2B716E000
heap
page read and write
6C3F20D000
stack
page read and write
94D927F000
stack
page read and write
36C9000
trusted library allocation
page read and write
1C36A000
heap
page read and write
2615F6B2000
trusted library allocation
page read and write
1CD902F9000
trusted library allocation
page read and write
1C80C000
heap
page read and write
D1F000
stack
page read and write
90F377E000
stack
page read and write
7FFD9BBA4000
trusted library allocation
page read and write
6C3E6BF000
stack
page read and write
15553500000
trusted library allocation
page read and write
155534BE000
trusted library allocation
page read and write
22ECF5D6000
trusted library allocation
page read and write
7FFD9BB70000
trusted library allocation
page read and write
4C1E000
stack
page read and write
20A61614000
heap
page read and write
36EF000
trusted library allocation
page read and write
22ECEA67000
trusted library allocation
page read and write
155534A2000
trusted library allocation
page read and write
22ECCBE0000
heap
page read and write
20A62EB7000
heap
page execute and read and write
2615F5E6000
trusted library allocation
page read and write
6C3E17F000
stack
page read and write
22ECCBD0000
trusted library allocation
page read and write
2615F7CE000
trusted library allocation
page read and write
2615C640000
trusted library allocation
page read and write
1C2BA483000
trusted library allocation
page read and write
2A73283B000
heap
page read and write
1C2C91F3000
trusted library allocation
page read and write
1CDE9630000
trusted library allocation
page read and write
1C2C94F5000
trusted library allocation
page read and write
261601EC000
trusted library allocation
page read and write
314E000
stack
page read and write
20A61820000
trusted library allocation
page read and write
1CD90021000
trusted library allocation
page read and write
329D000
heap
page read and write
2F39000
heap
page read and write
20A6433D000
trusted library allocation
page read and write
9883779000
stack
page read and write
32A6000
heap
page read and write
C4A7523000
stack
page read and write
1C2C91B4000
trusted library allocation
page read and write
1C2B7178000
heap
page read and write
1CD81091000
trusted library allocation
page read and write
2A732829000
heap
page read and write
2F22000
unkown
page readonly
1C2B71B4000
heap
page read and write
22ECCB90000
heap
page read and write
15553515000
trusted library allocation
page read and write
2596C044000
heap
page read and write
90F494C000
stack
page read and write
22ECE530000
trusted library allocation
page read and write
22ECCC10000
heap
page readonly
20A643A1000
trusted library allocation
page read and write
22ECFA72000
trusted library allocation
page read and write
94D8FEF000
stack
page read and write
73AC000
heap
page read and write
1010000
heap
page read and write
32A1000
heap
page read and write
3267000
heap
page read and write
A7D000
heap
page read and write
8C0000
stack
page read and write
2615FB92000
trusted library allocation
page read and write
1C2BAFA1000
trusted library allocation
page read and write
1CD81E27000
trusted library allocation
page read and write
1C2B8FB0000
heap
page read and write
7FFD9BB48000
trusted library allocation
page read and write
1C2BA182000
trusted library allocation
page read and write
73F1000
heap
page read and write
7FFD9BAC0000
trusted library allocation
page execute and read and write
EF24C7B000
stack
page read and write
1001000
unkown
page execute read
FDA000
trusted library allocation
page read and write
2A735CD2000
trusted library allocation
page read and write
1C2BA23D000
trusted library allocation
page read and write
1CD80D74000
trusted library allocation
page read and write
6D71000
heap
page read and write
32A3000
heap
page read and write
20A62EF0000
heap
page execute and read and write
950000
heap
page read and write
7484000
heap
page read and write
20A64C60000
trusted library allocation
page read and write
1B2C7000
heap
page read and write
20A615D0000
heap
page read and write
1C2C952A000
trusted library allocation
page read and write
1CDE7C90000
heap
page read and write
1CD9036B000
trusted library allocation
page read and write
AE4000
heap
page read and write
AD6000
heap
page read and write
2596C300000
heap
page read and write
7FFD9BBD0000
trusted library allocation
page read and write
2A7327E0000
heap
page read and write
22ECFA0F000
trusted library allocation
page read and write
EF24DFF000
stack
page read and write
20A63F10000
trusted library allocation
page read and write
ADB000
heap
page read and write
8C9000
stack
page read and write
7FFD9B9CB000
trusted library allocation
page execute and read and write
1CDE95F0000
heap
page readonly
7FFD9BE60000
trusted library allocation
page read and write
1C14E000
stack
page read and write
2A744551000
trusted library allocation
page read and write
7FF493AA0000
trusted library allocation
page execute and read and write
586000
stack
page read and write
6C3E53E000
stack
page read and write
7FFD9B9A3000
trusted library allocation
page execute and read and write
52CF000
stack
page read and write
7490000
heap
page read and write
3298000
heap
page read and write
1C2B8F20000
heap
page execute and read and write
7FFD9BB90000
trusted library allocation
page read and write
26435CB0000
heap
page read and write
6C3F10E000
stack
page read and write
1DB5E000
stack
page read and write
1C2D1180000
heap
page read and write
5461979000
stack
page read and write
C4A787F000
stack
page read and write
98836F6000
stack
page read and write
2596C000000
heap
page read and write
22ECCC5B000
heap
page read and write
98844CE000
stack
page read and write
22ECE4C0000
trusted library allocation
page read and write
90F3D7E000
stack
page read and write
1D40A000
stack
page read and write
20A6166D000
heap
page read and write
7491000
heap
page read and write
36E0000
trusted library allocation
page read and write
2A732760000
heap
page read and write
1C2BA0FA000
trusted library allocation
page read and write
1C2BA9E7000
trusted library allocation
page read and write
32CD000
heap
page read and write
7485000
heap
page read and write
1CDE9714000
heap
page read and write
7FFD9BCC4000
trusted library allocation
page read and write
1C2B7380000
trusted library allocation
page read and write
1230000
heap
page read and write
7FFD9BA60000
trusted library allocation
page execute and read and write
20A615DA000
heap
page read and write
1CD902F1000
trusted library allocation
page read and write
EF24EFE000
stack
page read and write
2615C660000
trusted library allocation
page read and write
2615E0C0000
heap
page read and write
20A62EB0000
heap
page execute and read and write
1C2B9D7E000
trusted library allocation
page read and write
513C000
stack
page read and write
2615E496000
trusted library allocation
page read and write
9D7000
heap
page read and write
1CD80087000
trusted library allocation
page read and write
22ECF432000
trusted library allocation
page read and write
1C2C947B000
trusted library allocation
page read and write
1C2B7100000
heap
page read and write
3045000
heap
page read and write
1CD81002000
trusted library allocation
page read and write
7FFD9BE40000
trusted library allocation
page read and write
1CDE7DA4000
heap
page read and write
B11000
heap
page read and write
1C2BA4B7000
trusted library allocation
page read and write
2616E45C000
trusted library allocation
page read and write
328F000
heap
page read and write
3281000
heap
page read and write
32CD000
heap
page read and write
26435BD0000
heap
page read and write
328A000
heap
page read and write
6C3E3B6000
stack
page read and write
1CD811D6000
trusted library allocation
page read and write
32BC000
heap
page read and write
15553590000
trusted library allocation
page read and write
1C2BAFA6000
trusted library allocation
page read and write
C4A7A79000
stack
page read and write
9D0000
heap
page read and write
32A6000
heap
page read and write
90F47CE000
stack
page read and write
2A735551000
trusted library allocation
page read and write
1CD80D6B000
trusted library allocation
page read and write
A9E000
heap
page read and write
C4A7F7B000
stack
page read and write
988337F000
stack
page read and write
3248000
heap
page read and write
7FFD9BE77000
trusted library allocation
page read and write
C4A7BF7000
stack
page read and write
328B000
heap
page read and write
A8A000
heap
page read and write
7FFD9BB80000
trusted library allocation
page execute and read and write
327D000
heap
page read and write
22ECE4F0000
trusted library allocation
page read and write
20A63F0E000
trusted library allocation
page read and write
20A61830000
heap
page readonly
155534D0000
trusted library allocation
page read and write
20A73331000
trusted library allocation
page read and write
1CDE7B90000
heap
page read and write
2A732784000
heap
page read and write
15553470000
trusted library allocation
page read and write
4C60000
heap
page read and write
1C68B000
stack
page read and write
6C3E07E000
stack
page read and write
26435D5A000
heap
page read and write
C4A7EFE000
stack
page read and write
1CD81E22000
trusted library allocation
page read and write
15553460000
trusted library allocation
page read and write
5461B7E000
stack
page read and write
C4A89CA000
stack
page read and write
22ECEA77000
trusted library allocation
page read and write
AF5000
unkown
page readonly
2615DF08000
heap
page read and write
546274C000
stack
page read and write
73F1000
heap
page read and write
2A734777000
trusted library allocation
page read and write
26160211000
trusted library allocation
page read and write
1C2C9596000
trusted library allocation
page read and write
2616E431000
trusted library allocation
page read and write
3280000
heap
page read and write
C4A7CFB000
stack
page read and write
4B60000
heap
page read and write
374D000
trusted library allocation
page read and write
1CDE7CEC000
heap
page read and write
1C2B73C0000
trusted library allocation
page read and write
7FFD9BC20000
trusted library allocation
page execute and read and write
EF24F7B000
stack
page read and write
7391000
heap
page read and write
1CD8133C000
trusted library allocation
page read and write
1C2B71B7000
heap
page read and write
C4A7B78000
stack
page read and write
1C2BA53E000
trusted library allocation
page read and write
There are 1007 hidden memdumps, click here to show them.