IOC Report
h32trial.exe

loading gif

Files

File Path
Type
Category
Malicious
h32trial.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\PROGRA~2\HAWin32\~GLH001c.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH001e.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0021.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0023.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0025.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0027.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0029.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH002b.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH002d.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH002f.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0031.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0033.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0035.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0037.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0039.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH003b.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH003d.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH003f.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0041.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0043.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0045.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0047.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0049.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH004b.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH004d.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH004f.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0051.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0053.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH0056.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\PROGRA~2\HAWin32\~GLH005a.TMP (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HADLL32.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANCSOCK.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANCSSH.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANC_STD.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANXDRCT.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANXSOCK.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANXSSH.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HANXTAPI.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\HAWIN32.EXE (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\LFKODAK.DLL (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\My Files\UNINSTAL.EXE (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\My Files\UNWISE32.EXE (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\My Files\~GLH0001.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\My Files\~GLH0002.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\RESETREG.EXE (copy)
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\register.exe (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\temp.000
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0004.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0006.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0007.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0008.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0009.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH000a.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH000b.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH000c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH000d.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH000e.TMP
PE32 executable (console) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH001b.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH001d.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0020.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0022.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0024.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0026.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0028.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH002a.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH002c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH002e.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0030.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0032.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0034.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0036.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0038.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH003a.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH003c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH003e.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0040.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0042.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0044.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0046.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0048.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH004a.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH004c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH004e.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0050.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0052.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0054.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0055.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\~GLH0082.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\GLC7B3F.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\GLF873A.tmp (copy)
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\GLM7D54.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\vsetupt.exe (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\~GLH0000.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\~GLH0005.TMP
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\Fonts\hyperdk.fon (copy)
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
malicious
C:\Windows\Fonts\hyperlt.fon (copy)
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
malicious
C:\Windows\Fonts\~GLH0011.TMP
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
malicious
C:\Windows\Fonts\~GLH0012.TMP
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
malicious
C:\Windows\SysWOW64\vboxb410.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\vboxp410.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\vboxt410.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH005f.TMP
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0060.TMP
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0061.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0069.TMP
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH006a.TMP
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH006c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH006e.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0071.TMP
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0072.TMP
PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0074.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0075.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH007b.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH007c.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH007d.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH007e.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH007f.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\SysWOW64\~GLH0080.TMP
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Program Files (x86)\HAWin32\My Files\Direct Cabled Connection.haw (copy)
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\Direct Cabled Host.hhw (copy)
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\HyperACCESS Convert.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Fri Jan 20 08:38:58 2017, length=126976, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\HyperACCESS Graphics Viewer.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:35 2024, atime=Fri Jan 20 08:38:58 2017, length=57344, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\HyperACCESS Help.lnk
MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\HyperACCESS Host.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:35 2024, atime=Sat Jul 31 06:35:00 2004, length=31396, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\HyperACCESS.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:34 2024, atime=Sat Jul 31 06:34:58 2004, length=36016, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\Lists.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Thu Mar 28 09:18:36 2024, length=0, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\My Files.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Thu Mar 28 09:18:37 2024, length=4096, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\ReadMe.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Tue Oct 13 11:54:06 2009, length=33500, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\HyperACCESS\Uninstall.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:34 2024, atime=Tue Oct 27 08:50:06 2009, length=184048, window=hide
dropped
C:\Program Files (x86)\HAWin32\My Files\INSTALL.LOG
ASCII text, with CRLF line terminators
modified
C:\Program Files (x86)\HAWin32\My Files\Lists\pocia.txt (copy)
news or mail, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\sbiq.txt (copy)
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\usbbs158.lst (copy)
ISO-8859 text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\wclist.txt (copy)
ISO-8859 text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\~GLH0065.TMP
ISO-8859 text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\~GLH0066.TMP
ISO-8859 text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\~GLH0067.TMP
news or mail, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Lists\~GLH0068.TMP
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\Modem Host.hhw (copy)
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\TCPIP Host.hhw (copy)
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\connect.wav (copy)
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\discnct.wav (copy)
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\ha_auto.h (copy)
C source, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\incoming.wav (copy)
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\pcw1exp.was (copy)
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\pcw2exp.was (copy)
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\pcw3exp.was (copy)
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\uwuninst.ico (copy)
MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors
dropped
C:\Program Files (x86)\HAWin32\My Files\welcome.ans (copy)
ASCII text, with CRLF line terminators, with escape sequences
dropped
C:\Program Files (x86)\HAWin32\My Files\welcome.txt (copy)
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\xferabrt.wav (copy)
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 22050 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\xfercomp.wav (copy)
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11000 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0003.TMP
MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0014.TMP
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11000 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0015.TMP
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0016.TMP
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0017.TMP
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 22050 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0018.TMP
RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0019.TMP
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH001a.TMP
ASCII text, with CRLF line terminators, with escape sequences
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH005b.TMP
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH005c.TMP
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH005d.TMP
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH005e.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0062.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0063.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH0064.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\HAWin32\My Files\~GLH006b.TMP
C source, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\hagv.chm (copy)
MS Windows HtmlHelp Data
dropped
C:\Program Files (x86)\HAWin32\hagv.cnt (copy)
MS Windows help file Content, based "HAGV.HLP", ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\hagv.reg (copy)
Windows Registry text (Win95 or above)
dropped
C:\Program Files (x86)\HAWin32\hawin32.chm (copy)
MS Windows HtmlHelp Data
dropped
C:\Program Files (x86)\HAWin32\hawin32.cnt (copy)
MS Windows help file Content, based "hawin32.HLP", ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\hawin32.tlb (copy)
data
dropped
C:\Program Files (x86)\HAWin32\hguard.dat (copy)
data
dropped
C:\Program Files (x86)\HAWin32\readme.doc (copy)
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Program Files (x86)\HAWin32\~GLH000f.TMP
data
dropped
C:\Program Files (x86)\HAWin32\~GLH0010.TMP
data
dropped
C:\Program Files (x86)\HAWin32\~GLH001f.TMP
Windows Registry text (Win95 or above)
dropped
C:\Program Files (x86)\HAWin32\~GLH0057.TMP
MS Windows HtmlHelp Data
dropped
C:\Program Files (x86)\HAWin32\~GLH0058.TMP
MS Windows help file Content, based "HAGV.HLP", ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\~GLH0077.TMP
MS Windows HtmlHelp Data
dropped
C:\Program Files (x86)\HAWin32\~GLH0078.TMP
MS Windows help file Content, based "hawin32.HLP", ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\HAWin32\~GLH007a.TMP
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Graphics Viewer.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Fri Jan 20 08:38:58 2017, length=57344, window=hide
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Host.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Sat Jul 31 06:35:00 2004, length=31396, window=hide
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Sat Jul 31 06:34:58 2004, length=36016, window=hide
dropped
C:\Users\user\AppData\Local\Temp\~DF044EE02583271B97.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Local\Temp\~DF24A521FD556FD4D5.TMP
data
dropped
C:\Users\user\AppData\Local\Temp\~DF8013949CDE068A61.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Local\VirtualStore\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.lic
ASCII text, with CRLF line terminators
modified
C:\Users\user\AppData\Local\VirtualStore\os985612.bin
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Folder.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:37 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Thu Mar 28 09:18:37 2024, length=0, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\Uninstall.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Tue Oct 27 08:50:06 2009, length=184048, window=hide
dropped
C:\Windows\Fonts\Key-capn.ttf (copy)
TrueType Font data, 15 tables, 1st "OS/2", 14 names, Macintosh, Key CapsRegular14352839Key Caps NormalConverter: Windows Type 1 Installer V1.0d.
dropped
C:\Windows\Fonts\~GLH0013.TMP
TrueType Font data, 15 tables, 1st "OS/2", 14 names, Macintosh, Key CapsRegular14352839Key Caps NormalConverter: Windows Type 1 Installer V1.0d.
dropped
C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.lic
ASCII text, with CRLF line terminators
dropped
C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.prf
data
dropped
C:\Windows\SysWOW64\AMERICAN.VTD (copy)
data
dropped
C:\Windows\SysWOW64\VSPELLER.HLP (copy)
MS Windows 3.0 help, Mon Jun 26 07:46:43 1995, 15819 bytes
dropped
C:\Windows\SysWOW64\ws811164.ocx
data
dropped
C:\Windows\SysWOW64\~GLH0070.TMP
data
dropped
C:\Windows\SysWOW64\~GLH0079.TMP
MS Windows 3.0 help, Mon Jun 26 07:46:43 1995, 15819 bytes
dropped
C:\os985612.bin
data
dropped
There are 196 hidden files, click here to show them.