IOC Report
dllhost.exe

loading gif

Files

File Path
Type
Category
Malicious
dllhost.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\af.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ca.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\cs.pak.xUSdFhL29
OpenPGP Public Key
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\da.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\de.pak.xUSdFhL29
MPEG-4 LOAS
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\en-GB.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\en-US.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\es-419.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\es.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\et.pak.xUSdFhL29
SVr4 curses screen image, little-endian
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\fi.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\fil.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\fr.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\hr.pak.xUSdFhL29
DOS executable (COM)
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\hu.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\id.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\it.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ko.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\lt.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\lv.pak.xUSdFhL29
OpenPGP Public Key Version 6, Created Wed Jul 7 11:35:43 1999, Unknown Algorithm (0xd)
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ms.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\nb.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\nl.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\pl.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\pt-BR.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\pt-PT.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ro.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\sk.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\sl.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\sv.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\sw.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\tr.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\zh-CN.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\zh-TW.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\VisualElements\Logo.png.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\chrome_100_percent.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\resources.pak.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\ThirdPartyNotice.html.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppTracing_startedInBGMode.etl.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edb.log.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbres00001.jrs.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbres00002.jrs.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edbtmp.log.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\MSEdge.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{8ABD94FB-E7D6-84A6-A997-C918EDDE0AE5}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{923DD477-5846-686B-A659-0FCCD73851A8}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{BB044BFD-25B7-2FAA-22A8-6371A93E0456}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{BD3F924E-55FB-A1BA-9DE6-B50F9F2460AC}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{C1C6F8AC-40A3-0F5C-146F-65A9DC70BBB4}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{C804BBA7-FA5F-CBF7-8B55-2096E5F972CB}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{DAA168DE-4306-C8BC-8C11-B596240BDDED}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{E7A33582-E908-3379-5368-5999454DCD83}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{E8B84CFB-B069-BC13-F88F-170904F645E5}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_AutoGenerated_{F1118828-A0CC-5FEB-85C9-DBFFDF98434A}.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_InternetExplorer_Default.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_DATABASECOMPARE_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_EXCEL_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_MSACCESS_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_MSPUB_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_ONENOTE_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_OUTLOOK_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_OcPubMgr_exe_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_POWERPNT_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_SETLANG_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_SPREADSHEETCOMPARE_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_WINWORD_EXE_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_lync_exe_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_msoev_exe_15.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsAlarms_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsCalculator_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsSoundRecorder_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_AdministrativeTools.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Computer.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_ControlPanel.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Explorer.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_MediaPlayer32.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_RemoteDesktop.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Shell_RunDialog.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_MdSched_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_RecoveryDrive_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_SnippingTool_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WFS_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WF_msc.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_PowerShell_ISE_exe.xUSdFhL29
zlib compressed data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_WindowsPowerShell_v1_0_powershell_exe.xUSdFhL29
OpenPGP Public Key
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_charmap_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cleanmgr_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_cmd_exe.xUSdFhL29
DOS executable (COM)
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_comexp_msc.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_dfrgui_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_iscsicpl_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_magnify_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msconfig_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_msinfo32_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_mspaint_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_narrator_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_notepad_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_odbcad32_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_osk_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_printmanagement_msc.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_psr_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_quickassist_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}_services_msc.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_7-Zip_7-zip_chm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_7-Zip_7zFM_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Adobe_Acrobat DC_Acrobat_Acrobat_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Common Files_Microsoft Shared_Ink_mip_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{6D809377-6AF0-444B-8957-A3773F02200E}_Windows NT_Accessories_wordpad_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Au3Info_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Au3Info_x64_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Aut2Exe_Aut2exe_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Aut2Exe_Aut2exe_x64_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt v3 Website_url.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt3_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt3_x64_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoItX_AutoItX_chm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_AutoIt_chm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Examples.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_Extras.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_AutoIt3_SciTE_SciTE_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}_Java_jre-1_8_bin_javacpl_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_PowerShell_ISE_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_WindowsPowerShell_v1_0_powershell_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}_odbcad32_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\{F38BF404-1D43-42F2-9305-67DE0B28FC23}_regedit_exe.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storei.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m8f4v4pw.default\times.json.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\m8f4v4pw.default\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\bookmarkbackups\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\crashes\events\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\crashes\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583304861.b0fc05c3-ead2-408e-9808-728375d77a75.new-profile.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583304864.8c7e12a2-deef-4b63-9655-b8092c733a4d.event.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583304868.59f06e22-78e3-4143-9d34-bd19d6977013.main.jsonlz4.xUSdFhL29
OpenPGP Public Key
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583304869.4543e2b6-0dac-4484-972e-233c4ffdcfcd.first-shutdown.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583313113.1864eebe-a97d-4196-ba9e-40ba8339789c.health.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583313138.717ed3b2-ea8b-46bf-926c-0346b661d09a.event.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583313139.639d6aff-3521-475f-a165-426024f2d9f0.health.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\1696583313145.c52da37e-6215-4698-a8c6-7dbc7928eb26.main.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\2023-10\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\archived\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\db\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\events\background-update.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\events\events.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\events\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\374bde87-f199-4fac-a615-01ab90ab0bf7.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\3bf2aef3-40fb-4049-b0b1-de69ef442f80.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\44fdd5c8-5b97-4814-aaa2-3feb97513132.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\8351b15a-8c18-4057-9b61-d8f7b30b6b9a.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\aabf5a2e-4b35-4c83-b535-ad48f381cc40.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\adb8b18e-cd15-4384-96ad-7a24cb8036ae.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\b410c22f-bd2f-4284-b486-a9eaccce4c0d.xUSdFhL29
SysEx File -
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\b4543248-1d51-4481-ad31-df186015c172.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\c3c38e93-087d-4203-9b06-06d6d3074fb6.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\cb86a51f-0e87-4a29-bb85-0245769bc428.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\cc17ce6f-06b5-463f-bb50-565238b1adcf.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\d6417413-e26c-46c2-ab09-55872479ca45.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\e04bd3a6-7ee1-4fbc-ab75-afaa6d22d841.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\fa0c2f7b-2db4-4e24-b345-4ff05ffa9493.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\fb7b70db-f644-4d7e-96ca-497c509ef330.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\pending_pings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\tmp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\glean\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\session-state.json.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\state.json.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\datareporting\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\minidumps\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\1864eebe-a97d-4196-ba9e-40ba8339789c.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\4543e2b6-0dac-4484-972e-233c4ffdcfcd.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\59f06e22-78e3-4143-9d34-bd19d6977013.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\639d6aff-3521-475f-a165-426024f2d9f0.xUSdFhL29
locale data table
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\717ed3b2-ea8b-46bf-926c-0346b661d09a.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\8c7e12a2-deef-4b63-9655-b8092c733a4d.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\b0fc05c3-ead2-408e-9808-728375d77a75.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\c52da37e-6215-4698-a8c6-7dbc7928eb26.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\saved-telemetry-pings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\security_state\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionstore-backups\previous.jsonlz4.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\sessionstore-backups\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1451318868ntouromlalnodry--epcr.sqlite.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\1657114595AmcateirvtiSty.sqlite.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2823318777ntouromlalnodry--naod.sqlite.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2918063365piupsah.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\2918063365piupsah.sqlite.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3561288849sdhlie.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3561288849sdhlie.sqlite.xUSdFhL29
OpenPGP Secret Key
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite.xUSdFhL29
data
dropped
malicious
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\sp4c0p22.default-release\storage\permanent\chrome\idb\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\Desktop\AAAAAAAAAAA (copy)
data
dropped
malicious
C:\Users\user\Desktop\BBBBBBBBBBB (copy)
data
dropped
malicious
C:\Users\user\Desktop\CCCCCCCCCCC (copy)
data
dropped
malicious
C:\Users\user\Desktop\DDDDDDDDDDD (copy)
data
dropped
malicious
C:\Users\user\Desktop\EEEEEEEEEEE (copy)
data
dropped
malicious
C:\Users\user\Desktop\FFFFFFFFFFF (copy)
data
dropped
malicious
C:\Users\user\Desktop\GGGGGGGGGGG (copy)
data
dropped
malicious
C:\Users\user\Desktop\HHHHHHHHHHH (copy)
data
dropped
malicious
C:\Users\user\Desktop\IIIIIIIIIII (copy)
data
dropped
malicious
C:\Users\user\Desktop\JJJJJJJJJJJ (copy)
data
dropped
malicious
C:\Users\user\Desktop\KKKKKKKKKKK (copy)
data
dropped
malicious
C:\Users\user\Desktop\LLLLLLLLLLL (copy)
data
dropped
malicious
C:\Users\user\Desktop\MMMMMMMMMMM (copy)
data
dropped
malicious
C:\Users\user\Desktop\NNNNNNNNNNN (copy)
data
dropped
malicious
C:\Users\user\Desktop\OOOOOOOOOOO (copy)
data
dropped
malicious
C:\Users\user\Desktop\PPPPPPPPPPP (copy)
data
dropped
malicious
C:\Users\user\Desktop\QQQQQQQQQQQ (copy)
data
dropped
malicious
C:\Users\user\Desktop\RRRRRRRRRRR (copy)
data
dropped
malicious
C:\Users\user\Desktop\SSSSSSSSSSS (copy)
data
dropped
malicious
C:\Users\user\Desktop\TTTTTTTTTTT (copy)
data
dropped
malicious
C:\Users\user\Desktop\UUUUUUUUUUU (copy)
data
dropped
malicious
C:\Users\user\Desktop\VVVVVVVVVVV (copy)
data
dropped
malicious
C:\Users\user\Desktop\WWWWWWWWWWW (copy)
data
dropped
malicious
C:\Users\user\Desktop\XXXXXXXXXXX (copy)
data
dropped
malicious
C:\Users\user\Desktop\YYYYYYYYYYY (copy)
data
dropped
malicious
C:\Users\user\Desktop\ZZZZZZZZZZZ (copy)
data
dropped
malicious
C:\Users\user\Desktop\dllhost.exe
data
modified
malicious
C:\Users\user\Documents\Outlook Files\Outlook Data File - NoEmail.pst.xUSdFhL29
data
dropped
malicious
C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp.xUSdFhL29
data
dropped
malicious
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\AAAAAAAAAAA (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\BBBBBBBBBBB (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\CCCCCCCCCCC (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\DDDDDDDDDDD (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\EEEEEEEEEEE (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\FFFFFFFFFFF (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\GGGGGGGGGGG (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\HHHHHHHHHHH (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\IIIIIIIIIII (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\JJJJJJJJJJJ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\KKKKKKKKKKK (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\LLLLLLLLLLL (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\MMMMMMMMMMM (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\NNNNNNNNNNN (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\OOOOOOOOOOO (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\PPPPPPPPPPP (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\QQQQQQQQQQQ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\RRRRRRRRRRR (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\SSSSSSSSSSS (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\TTTTTTTTTTT (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\UUUUUUUUUUU (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\VVVVVVVVVVV (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\WWWWWWWWWWW (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\XXXXXXXXXXX (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\YYYYYYYYYYY (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\ZZZZZZZZZZZ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\AAAAAAAAAAA (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\BBBBBBBBBBB (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\CCCCCCCCCCC (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\DDDDDDDDDDD (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\EEEEEEEEEEE (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\FFFFFFFFFFF (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\GGGGGGGGGGG (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\HHHHHHHHHHH (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\IIIIIIIIIII (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\JJJJJJJJJJJ (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\KKKKKKKKKKK (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\LLLLLLLLLLL (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\MMMMMMMMMMM (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\NNNNNNNNNNN (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\OOOOOOOOOOO (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\PPPPPPPPPPP (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\QQQQQQQQQQQ (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\RRRRRRRRRRR (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\SSSSSSSSSSS (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\TTTTTTTTTTT (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\UUUUUUUUUUU (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\VVVVVVVVVVV (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\WWWWWWWWWWW (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\XXXXXXXXXXX (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\YYYYYYYYYYY (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\ZZZZZZZZZZZ (copy)
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini
OpenPGP Public Key
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\AAAAAAAAAAA (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\BBBBBBBBBBB (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\CCCCCCCCCCC (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\DDDDDDDDDDD (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\EEEEEEEEEEE (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\FFFFFFFFFFF (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\GGGGGGGGGGG (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\HHHHHHHHHHH (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\IIIIIIIIIII (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\JJJJJJJJJJJ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\KKKKKKKKKKK (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\LLLLLLLLLLL (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\MMMMMMMMMMM (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\NNNNNNNNNNN (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\OOOOOOOOOOO (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\PPPPPPPPPPP (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\QQQQQQQQQQQ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\RRRRRRRRRRR (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\SSSSSSSSSSS (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\TTTTTTTTTTT (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\UUUUUUUUUUU (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\VVVVVVVVVVV (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\WWWWWWWWWWW (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\XXXXXXXXXXX (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\YYYYYYYYYYY (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\ZZZZZZZZZZZ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\AAAAAAAAAAA (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\BBBBBBBBBBB (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\CCCCCCCCCCC (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\DDDDDDDDDDD (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\EEEEEEEEEEE (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\FFFFFFFFFFF (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\GGGGGGGGGGG (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\HHHHHHHHHHH (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\IIIIIIIIIII (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\JJJJJJJJJJJ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\KKKKKKKKKKK (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\LLLLLLLLLLL (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\MMMMMMMMMMM (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\NNNNNNNNNNN (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\OOOOOOOOOOO (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\PPPPPPPPPPP (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\QQQQQQQQQQQ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\RRRRRRRRRRR (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\SSSSSSSSSSS (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\TTTTTTTTTTT (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\UUUUUUUUUUU (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\VVVVVVVVVVV (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\WWWWWWWWWWW (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\XXXXXXXXXXX (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\YYYYYYYYYYY (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\ZZZZZZZZZZZ (copy)
data
dropped
C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini
data
dropped
C:\$WinREAgent\Scratch\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\$WinREAgent\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\ProgramData\xUSdFhL29.ico
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
C:\Users\user\.curlrc.xUSdFhL29
data
dropped
C:\Users\user\.ms-ad\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\3D Objects\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\CURRENT.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\076dd576a8178299_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0a71ed411241f66a_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0b05805acd0d1882_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0.xUSdFhL29
COM executable for DOS
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\27d6cd255a96bfd9_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\28daa88523128699_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2d207d5589cabc48_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\31f9e8ec74b3086f_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\431888171713135e_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4ca3cb58378aaa3f_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\627265196527eec1_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\64766d63a539c3ca_0.xUSdFhL29
DOS executable (COM)
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6580eb6b2e190c0b_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6a34b53951ee8d83_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6e8773c5f8211d0f_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0.xUSdFhL29
DOS executable (COM, 0x8C-variant)
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\72d9f526d2e2e7c8_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\78bff3512887b83d_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7f540d5ac2d70ada_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0.xUSdFhL29
OpenPGP Secret Key Version 5
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0.xUSdFhL29
DOS executable (COM)
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b381493e8d0a8910_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf8eae3dcaf681ca_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\c03c0918f3ea6b81_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d5dedf551f4d1592_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\da25e12456b6429b_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\e0924daf8f4398dc_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\e4666359b4558d3e_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\e58e492b0f04240a_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f1811476c6b2cc5c_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f29d20371983e164_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\the-real-index.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index-dir\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\CURRENT.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\MANIFEST-000001.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LocalPrefs.json.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\MANIFEST-000001.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Cookies.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Reporting and NEL.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\CURRENT.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\MANIFEST-000001.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links.xUSdFhL29
data
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cookie\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\Linguistics\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\Adobe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\LocalLow\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\ARM\Acrobat_23.006.20320\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\ARM\S\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\ARM\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\ARM\{291AA914-A987-4CE9-BD63-0C0A92D435E5}\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt23.lst.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID.xUSdFhL29
COM executable for DOS
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner.xUSdFhL29
MIPSEL ECOFF executable not stripped - version 86.102
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\Edit_InApp_Aug2020.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Color\ACECache11.lst.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Adobe\Color\Profiles\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\Color\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Adobe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\114.0.5735.90.manifest.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Extensions\external_extensions.json.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Extensions\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Installer\chrome.7z.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Installer\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\am.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ar-XB.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ar.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\bg.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\bn.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\el.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\en-XA.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\fa.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\gu.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\he.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\hi.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ja.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\kn.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ml.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\mr.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ru.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\sr.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ta.pak.xUSdFhL29
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\te.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\th.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\uk.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\ur.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\vi.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\Locales\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\MEIPreload\manifest.json.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\MEIPreload\preloaded_data.pb.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\MEIPreload\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\VisualElements\SmallLogo.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\VisualElements\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\chrome_200_percent.pak.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\icudtl.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\nacl_irt_x86_64.nexe.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\vk_swiftshader_icd.json.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\114.0.5735.90\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\SetupMetrics\20240207155724.pma.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\SetupMetrics\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\Application\chrome.VisualElementsManifest.xml.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\Application\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\User Data\Crashpad\attachments\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\User Data\Crashpad\reports\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\User Data\Crashpad\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Chromium\User Data\Crashpad\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\User Data\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Chromium\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jcp.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jtx.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00001.jrs.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00002.jrs.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\USStmp.jtx.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\store.jfm.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\store.vol.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\UnistoreDB\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Comms\Unistore\data\AggregateCache.uca.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Comms\Unistore\data\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Comms\Unistore\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Comms\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\Connected Devices Platform certificates.sst.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user.cdp.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user.cdpresource.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db-wal.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\ActivitiesCache.db.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\D3DSCache\e8010882af4f153f\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.val.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\D3DSCache\e8010882af4f153f\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\D3DSCache\f4d41c5d09ae781\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.val.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\D3DSCache\f4d41c5d09ae781\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\D3DSCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\AutofillStates\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-651FCE72-153C.pma.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\65F8751E-2CCD-4E92-9B38-65C515E8BEA8
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\onenote.exe.db
SQLite 3.x database, last written using SQLite version 3023002, writer version 2, read version 2, file counter 2, database pages 1, cookie 0, schema 0, largest root page 1, unknown 0 encoding, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\onenote.exe.db-journal
SQLite Rollback Journal
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\onenote.exe.db-shm
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\onenote.exe.db-wal
SQLite Write-Ahead Log, version 3007000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000000.bin
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000001.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000002.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000003.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000004.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000005.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000006.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000007.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000008.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000009.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000A.bin (copy)
DIY-Thermocam raw data (Lepton 2.x), scale 5339--4754, spot sensor temperature 0.000000, unit celsius, color scheme 1, minimum point enabled, maximum point enabled, userbration: offset 0.000000, slope 2.658576
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000B.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000C.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000D.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000E.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000G.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000H.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000I.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000J.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000K.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000L.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000M.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000N.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000O.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000P.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000Q.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000R.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000S.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000T.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000U.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000000V.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000010.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000011.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000012.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000013.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000014.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000015.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000016.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000017.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000018.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000019.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001A.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001B.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001C.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001D.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001E.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001G.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001H.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001I.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001J.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001K.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001L.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001M.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001N.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001O.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001P.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001Q.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001R.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001S.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001T.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001U.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000001V.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000020.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000021.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000022.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000023.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000024.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000025.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000026.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000027.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000028.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000029.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002A.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002B.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002C.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002D.bin (copy)
PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002E.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002F.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002G.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002H.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002I.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002J.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002K.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002L.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002M.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002N.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002O.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002P.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002Q.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002R.bin (copy)
PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002S.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002T.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002U.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000002V.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000030.bin (copy)
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000031.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000032.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000033.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000034.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000035.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000036.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000037.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000038.bin (copy)
PNG image data, 40 x 623, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000039.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003A.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003B.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003C.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003D.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003E.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003G.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003H.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003I.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003J.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003K.bin (copy)
PNG image data, 60 x 336, 4-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003L.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003M.bin (copy)
PNG image data, 40 x 617, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003N.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003O.bin (copy)
PNG image data, 50 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003P.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003Q.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003R.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003S.bin (copy)
PNG image data, 77 x 627, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003T.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003U.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000003V.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000040.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000041.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000042.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000043.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000044.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000045.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000046.bin (copy)
PNG image data, 176 x 513, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000047.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000048.bin (copy)
PNG image data, 40 x 650, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000049.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004A.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004B.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004C.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004D.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004E.bin (copy)
PNG image data, 50 x 556, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004G.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004H.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004I.bin (copy)
PNG image data, 171 x 552, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004J.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004K.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004L.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004M.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004N.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004O.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004P.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004Q.bin (copy)
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004R.bin (copy)
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004S.bin (copy)
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004T.bin (copy)
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004U.bin (copy)
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000004V.bin (copy)
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000050.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000051.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000052.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000053.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000054.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000055.bin (copy)
PNG image data, 50 x 500, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000056.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000057.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000058.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000059.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005A.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005B.bin (copy)
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005C.bin (copy)
PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005D.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005E.bin (copy)
PNG image data, 39 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005G.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005H.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005I.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005J.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005K.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005L.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005M.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005N.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005O.bin (copy)
PNG image data, 39 x 579, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005P.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005Q.bin (copy)
PNG image data, 30 x 700, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005R.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005S.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005T.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005U.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000005V.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000060.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000061.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000062.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000063.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000064.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000065.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000066.bin (copy)
PNG image data, 85 x 470, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000067.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000068.bin (copy)
PNG image data, 88 x 574, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\00000069.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006A.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006B.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006C.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006D.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006E.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006F.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006G.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006H.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006I.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006J.bin (copy)
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006K.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006L.bin (copy)
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\0000006M.bin (copy)
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\header
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000001.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000002.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000003.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000004.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000005.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000006.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000007.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000008.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000009.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000A.bin
DIY-Thermocam raw data (Lepton 2.x), scale 5339--4754, spot sensor temperature 0.000000, unit celsius, color scheme 1, minimum point enabled, maximum point enabled, userbration: offset 0.000000, slope 2.658576
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000B.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000C.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000D.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000E.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000G.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000H.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000I.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000J.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000K.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000L.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000M.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000N.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000O.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000P.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000Q.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000R.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000S.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000T.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000U.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000V.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000010.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000011.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000012.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000013.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000014.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000015.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000016.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000017.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000018.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000019.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001A.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001B.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001C.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001D.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001E.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001G.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001H.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001I.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001J.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001K.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001L.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001M.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001N.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001O.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001P.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001Q.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001R.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001S.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001T.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001U.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000001V.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000020.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000021.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000022.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000023.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000024.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000025.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000026.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000027.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000028.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000029.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002A.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002B.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002C.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002D.bin
PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002E.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002F.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002G.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002H.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002I.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002J.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002K.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002L.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002M.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002N.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002O.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002P.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002Q.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002R.bin
PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002S.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002T.bin
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002U.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000002V.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000030.bin
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000031.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000032.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000033.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000034.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000035.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000036.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000037.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000038.bin
PNG image data, 40 x 623, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000039.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003A.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003B.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003C.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003D.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003E.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003G.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003H.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003I.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003J.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003K.bin
PNG image data, 60 x 336, 4-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003L.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003M.bin
PNG image data, 40 x 617, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003N.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003O.bin
PNG image data, 50 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003P.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003Q.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003R.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003S.bin
PNG image data, 77 x 627, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003T.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003U.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000003V.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000040.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000041.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000042.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000043.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000044.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000045.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000046.bin
PNG image data, 176 x 513, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000047.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000048.bin
PNG image data, 40 x 650, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000049.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004A.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004B.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004C.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004D.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004E.bin
PNG image data, 50 x 556, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004G.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004H.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004I.bin
PNG image data, 171 x 552, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004J.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004K.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004L.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004M.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004N.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004O.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004P.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004Q.bin
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004R.bin
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004S.bin
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004T.bin
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004U.bin
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000004V.bin
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000050.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000051.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000052.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000053.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000054.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000055.bin
PNG image data, 50 x 500, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000056.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000057.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000058.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000059.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005A.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005B.bin
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005C.bin
PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005D.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005E.bin
PNG image data, 39 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005G.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005H.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005I.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005J.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005K.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005L.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005M.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005N.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005O.bin
PNG image data, 39 x 579, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005P.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005Q.bin
PNG image data, 30 x 700, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005R.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005S.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005T.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005U.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000005V.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000060.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000061.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000062.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000063.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000064.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000065.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000066.bin
PNG image data, 85 x 470, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000067.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000068.bin
PNG image data, 88 x 574, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000069.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006A.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006B.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006C.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006D.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006E.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006F.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006G.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006H.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006I.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006J.bin
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006K.bin
data
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006L.bin
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000006M.bin
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\26310719480\squaretile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\26310719480\tinytile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\26310719480\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\38975140460\squaretile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\38975140460\tinytile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\38975140460\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\6501008900\squaretile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\6501008900\tinytile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\6501008900\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\7603651830\squaretile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\7603651830\tinytile.png.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\7603651830\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\PinnedTiles\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AppData\CacheStorage\CacheStorage.edb.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AppData\CacheStorage\CacheStorage.jfm.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AppData\CacheStorage\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\Local\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\Roaming\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat.xUSdFhL29
DOS executable (COM, 0x8C-variant)
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.1.7_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.1.7_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.1.7_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.2.2_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.2.2_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Framework.2.2_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.1.7_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.1.7_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.1.7_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.2.2_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.2.2_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.NET.Native.Runtime.2.2_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite-wal.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\Cache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\TokenBroker\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.edb.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\CacheStorage.jfm.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\CacheStorage\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.jfm.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\edb.chk.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\Indexed DB\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_BingWeather_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_GetHelp_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Getstarted_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_MSPaint_8wekyb3d8bbwe!Microsoft_MSPaint.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Microsoft3DViewer_8wekyb3d8bbwe!Microsoft_Microsoft3DViewer.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_MicrosoftOfficeHub_8wekyb3d8bbwe!Microsoft_MicrosoftOfficeHub.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_MicrosoftSolitaireCollection_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_MicrosoftStickyNotes_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_MixedReality_Portal_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Office_OneNote_8wekyb3d8bbwe!microsoft_onenoteim.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_People_8wekyb3d8bbwe!x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_ScreenSketch_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsCamera_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsFeedbackHub_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsMaps_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_WindowsStore_8wekyb3d8bbwe!App.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_Photos_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_Windows_SecHealthUI_cw5n1h2txyewy!SecHealthUI.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_XboxApp_8wekyb3d8bbwe!Microsoft_XboxApp.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_YourPhone_8wekyb3d8bbwe!App.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_ZuneMusic_8wekyb3d8bbwe!Microsoft_ZuneMusic.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\Microsoft_ZuneVideo_8wekyb3d8bbwe!Microsoft_ZuneVideo.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\microsoft_windowscommunicationsapps_8wekyb3d8bbwe!microsoft_windowslive_calendar.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\microsoft_windowscommunicationsapps_8wekyb3d8bbwe!microsoft_windowslive_mail.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\AppIconCache\100\windows_immersivecontrolpanel_cw5n1h2txyewy!microsoft_windows_immersivecontrolpanel.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\AppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\LocalState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\RoamingState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\SystemAppData\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\TempState\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\Temp\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\AC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\windows_ie_ac_001\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Packages\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\PeerDistRepub\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Fonts\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Licenses\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\Microsoft.WindowsAlarms\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\SettingsContainer\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\8wekyb3d8bbwe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Publishers\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\SolidDocuments\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\SolidDocuments\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\ONENOTE\App1713559686589071100_BF219EAB-68E9-4905-93BD-BE191E9EA8BB.log
data
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\ONENOTE\App1713559686589982700_BF219EAB-68E9-4905-93BD-BE191E9EA8BB.log
data
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1713559629831949800_E4C9A697-1A38-43A9-9F40-2F6943D7CEAC.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1713559629832404500_E4C9A697-1A38-43A9-9F40-2F6943D7CEAC.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\DC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\Adobe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2023-10-06 11-38-51-038.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2023-10-06 11-39-03-058.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log.xUSdFhL29
data
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrobat_sbx\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrocef_low\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\SearchEmbdIndex\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\acrord32_super_sbx\Adobe\Acrobat\DC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\{03B4186C-8EE1-43FB-852C-B64FB94A05DF}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Temp\{05421DAD-C450-406B-A482-CD175C5F83F7}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{072D9425-4FF4-4B0B-99CB-2D36B8C68342}
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{07B3E846-B595-49F1-BA3F-F87A9D4759BB}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 17x608, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0A1B7ECC-A7AE-46A3-8FB3-64E2CF63253D}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:18:09], progressive, precision 8, 164x641, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0B6EE134-D571-4823-9FCD-EEE4A156E81F}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 357x69, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0CE28CFD-E3EF-4534-8A3F-BDD81BE2E4A3}
PNG image data, 813 x 99, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{0D8A8E03-5CF8-48EC-B80B-088A39D0C8F0}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0DA7A957-ECBF-4A8E-80F0-548AEF23D6BE}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0E8F8254-7F26-48CD-997D-2637BDFEA0F9}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{0EE86DD6-EA87-42E4-9ED9-A58B1B40556D}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:15:20], progressive, precision 8, 604x784, components 3
dropped
C:\Users\user\AppData\Local\Temp\{137AE37A-C7CB-4697-98E6-264BE37C12AC}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Temp\{14FACA6B-3836-4451-BE01-E4601241EED2}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 814x105, components 3
dropped
C:\Users\user\AppData\Local\Temp\{15D1AD14-D54F-4967-BFF1-BF7D4102AEAA}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{17DDE63B-21B7-4BF4-A941-7CF9A50AAAB6}
PNG image data, 39 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{18451A2C-3AB5-4C8F-A15E-2927C863ACC6}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:27:10], progressive, precision 8, 102x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{1DBA7BF8-5600-432B-8F0E-6A9CF8A82B00}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{1F033D1E-6835-4D69-AE14-4AEB69ABFADC}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:44:07], progressive, precision 8, 611x163, components 3
dropped
C:\Users\user\AppData\Local\Temp\{20A4AE70-F7CB-4301-A263-DE7E9E9A7143}
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{20B1929C-4438-48C2-8B4E-5356CC471B5F}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{2437CF16-85AE-45DC-B14E-B1B3F41CADF7}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Temp\{26D761C2-A41A-4F97-A4AE-A8E79F65EB6E}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 780x107, components 3
dropped
C:\Users\user\AppData\Local\Temp\{2F895AFE-196E-4160-81AB-B70CCBA9DB8D}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:08:07], baseline, precision 8, 595x450, components 3
dropped
C:\Users\user\AppData\Local\Temp\{35225883-E2AC-44A2-9EFC-BB87EE5F1D5C}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{3BB4C234-7D53-4106-A721-5516EC44C925}
PNG image data, 40 x 617, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{422BB1CC-BFA1-4378-A519-07FA631A384B}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{426C88EE-2B0D-4B37-9A00-A1C9B3270DC1}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{441809B7-03C0-4B67-903F-5ECE127D3926}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 70x626, components 3
dropped
C:\Users\user\AppData\Local\Temp\{44F6DB2D-AC97-48FC-AF73-C8CBECF32B8A}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{47246BC9-9DEA-47E1-BD39-D3D732CBE481}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{4BF8EF49-C8C6-4025-9478-28DBA778A1BE}
PNG image data, 50 x 600, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{54FFAA10-734A-4FE8-AD02-1F4C152D74B9}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{5D97F17A-A24A-4609-9882-FAF69C9A5EB2}
PNG image data, 3005 x 184, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{60CEC039-3478-4AE6-8043-5B68E974857B}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 262x277, components 3
dropped
C:\Users\user\AppData\Local\Temp\{665F8EBD-CFD6-4516-BC55-1092BEE21D2D}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 700x114, components 3
dropped
C:\Users\user\AppData\Local\Temp\{681B87DD-DB27-49AB-A8B2-127C0438D6DD}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{69ABA3C5-4253-4166-BA92-B1391FF627F2}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{6DEFC066-21EB-4F31-A666-70E2FF3D7899}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{73B1E6E8-D711-4DD1-9933-D7B35AE866C3}
PNG image data, 177 x 123, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{747075A5-99B9-444D-B8C8-EB9738A8B083}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{7561BF6D-A2E8-40C5-8A59-005B5704D2A7}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 14x341, components 3
dropped
C:\Users\user\AppData\Local\Temp\{77D29C9F-EC9E-4D8A-9518-D3EAD632F04F}
PNG image data, 50 x 500, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{7B316231-C133-4EBB-800B-4134CF45EC7B}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 95x498, components 3
dropped
C:\Users\user\AppData\Local\Temp\{7CB833B4-051B-4515-B28F-D368D82EED8C}
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Temp\{807B8D35-F567-4436-8623-9C3B8BE9C9E6}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 814x45, components 3
dropped
C:\Users\user\AppData\Local\Temp\{82288A54-1DC7-4010-B3F5-AE71D81CDF4F}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:09:29], progressive, precision 8, 609x675, components 3
dropped
C:\Users\user\AppData\Local\Temp\{87CB7343-04D9-4F2D-809B-1189182DBA38}
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Temp\{88BB0C7E-1168-4527-9244-376C6A2A9AE2}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{890DF388-8D7B-411D-9514-AA9A42F2DC65}
PNG image data, 39 x 579, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{8E64D7B3-19F8-4294-8043-BF67B18D5742}
PNG image data, 77 x 627, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{938207AD-16F7-4201-8BC0-41BCA4AFC86F}
PNG image data, 50 x 556, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{93A9AD9D-395A-4663-88EB-19ED988941F0}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{988F19BC-0A96-4992-934C-2C683AAB76AA}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 105x441, components 3
dropped
C:\Users\user\AppData\Local\Temp\{A1032B79-EDCE-4E22-B100-FDD9AA6AD5D8}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:06:24], progressive, precision 8, 38x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{A6E8A28A-DCCB-4FE5-8C44-2F043471EA5E}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:12:29], progressive, precision 8, 598x766, components 3
dropped
C:\Users\user\AppData\Local\Temp\{A8F6391E-410D-4087-8D21-8B2B8D1FFB1B}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{AA138BFA-5006-4C2F-AFDA-B07A7BC04E6C}
PNG image data, 176 x 513, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{AB83CAE9-CEDB-46F6-B7ED-64C01E789C34}
PNG image data, 189 x 305, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{ACCE3D7E-4290-4594-9E20-16C3A125D5A0}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:11:38], progressive, precision 8, 577x757, components 3
dropped
C:\Users\user\AppData\Local\Temp\{AD44D013-DF86-4BF6-B2A0-A004F92DA760}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{AFBECC80-E3CD-4D84-978C-288DDC16E9C9}
PNG image data, 30 x 700, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{B6FB9321-7520-44B9-A5D0-410EB6D9D81F}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{B825E5A0-23FC-44FD-AF9A-722A129E1FA4}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{B8934E1C-3E10-49F5-9732-4319D2944517}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 276x139, components 3
dropped
C:\Users\user\AppData\Local\Temp\{B8E4D597-DAFB-449D-BDCA-ABCCC3E67C65}
PNG image data, 85 x 470, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{B9E3289F-3975-40B5-8084-13E924CFE5C3}
PNG image data, 60 x 336, 4-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{BB1102B8-7D90-4D31-8A7D-BD2372152187}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{BBB30EFE-D757-42E8-95A1-BACC08C05FF0}
PNG image data, 171 x 552, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{BE62715C-FBF9-444D-95D2-5CE09CDB8FA6}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{C9A0E309-DED0-4E84-AFBB-FD3156BBFC3B}
PNG image data, 40 x 623, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{CC426BBA-6E79-4C63-8B7A-FBDE182259AE}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{D0DE6F9F-B0C4-4707-986D-1270A7280D0B}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{D189EF91-D21E-4646-B635-42BAAEF2232B}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 69x630, components 3
dropped
C:\Users\user\AppData\Local\Temp\{D915E3C0-20C3-4F02-A69F-1A612675FF23}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:26:15], progressive, precision 8, 216x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{E10E8EBC-1B75-4990-BD73-661463108EA3}
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Temp\{E2716FA4-6324-4BE2-BB15-BF1589251478}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{E4A279E9-8042-470D-A730-F6BE69003AEF}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:05:55], progressive, precision 8, 612x618, components 3
dropped
C:\Users\user\AppData\Local\Temp\{EAB5CBE0-0D95-4807-8C89-51A0A10548CF}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 76x97, components 3
dropped
C:\Users\user\AppData\Local\Temp\{ECC99170-A1BD-496D-8939-CA1841456C19}
Windows Enhanced Metafile (EMF) image data version 0x10000
dropped
C:\Users\user\AppData\Local\Temp\{EEEA7344-B10E-4B8A-82A0-63BDAD2218C5}
PNG image data, 40 x 650, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{F0EB9153-9DCB-4736-8CF1-766A1E8D6039}
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 728x77, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F1804207-0691-4B3C-A2DA-95091691D45E}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F24A2F6A-DB89-4E21-B498-C130E63C0466}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2004:03:04 13:19:29], progressive, precision 8, 221x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F28932C2-5263-4E1D-AAF9-0C85EA417019}
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 613x144, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F3752AC6-E774-40A1-B327-71D81B56B8F9}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F5461164-CE0D-4799-BBE3-8C86AB161F69}
PNG image data, 88 x 574, 8-bit colormap, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\{F56C5AAD-17A8-4ACC-BCAE-CDA4D1A78788}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F921A826-0423-4BC0-B4D3-B4BC1DE5797F}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:10:32], progressive, precision 8, 594x773, components 3
dropped
C:\Users\user\AppData\Local\Temp\{F9286F33-2C52-45DB-BD32-5D1627E991D9}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Local\Temp\{FAF52D8E-AD07-47D8-BCE9-B52058294290}
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS Windows, datetime=2004:03:12 11:13:06], progressive, precision 8, 570x779, components 3
dropped
C:\Users\user\AppData\Local\Temp\{FB41CE62-0B20-466D-9DEC-6B3CB3F6991F}
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 612x792, components 3
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Collab\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Forms\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\JSCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_store.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\ES_session_storek.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\TMDocs.sav.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\TMGrpPrm.sav.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\Preflight Acrobat Continuous\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Acrobat\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\CRLogs\crashlogs\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\CRLogs\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Flash Player\NativeCache\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Flash Player\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Headlights\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Linguistics\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\LogTransport2CC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\LogTransport2\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\RTTransfer\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Sonar\SonarCC\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\Sonar\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Adobe\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Microsoft\OneNote\16.0\Preferences.dat
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0V9S92NBTKWLXKST1EAR.temp
Matlab v4 mat-file (little endian) \253\373\277\272, sparse, rows 1, columns 0, imaginary
modified
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1bc9bbbe61f14501.customDestinations-ms (copy)
Matlab v4 mat-file (little endian) \253\373\277\272, sparse, rows 1, columns 0, imaginary
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has command line arguments, Archive, ctime=Fri Oct 6 08:18:13 2023, mtime=Fri Apr 19 19:48:26 2024, atime=Fri Oct 6 08:18:14 2023, length=172960, window=hide
dropped
C:\Users\user\AppData\Roaming\Mozilla\Extensions\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20230927232528.xUSdFhL29
data
dropped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\events\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Crash Reports\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Pending Pings\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\com.adobe.dunamis\56079431-ea46-4833-94f9-1ff5658cdb1c\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\com.adobe.dunamis\61f56613-c62c-4b17-84dd-62b60d5776aa\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\com.adobe.dunamis\6d9d9777-7ded-4768-8191-9a707d72b009\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\com.adobe.dunamis\f2eb6c79-671d-4de2-b7be-3b2eea7abc47\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Roaming\com.adobe.dunamis\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\DUUDTUBZFW.docx.xUSdFhL29
data
dropped
C:\Users\user\Documents\DUUDTUBZFW\DUUDTUBZFW.docx.xUSdFhL29
data
dropped
C:\Users\user\Documents\DUUDTUBZFW\EIVQSAOTAQ.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\DUUDTUBZFW\EOWRVPQCCS.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\DUUDTUBZFW\EWZCVGNOWT.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\DUUDTUBZFW\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\EIVQSAOTAQ.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\EIVQSAOTAQ.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS.docx.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\EIVQSAOTAQ.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\EOWRVPQCCS.docx.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\GIGIYTFFYT.pdf.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\QCOILOQIKC.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\TQDFJHPUIU.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\ZIPXYXWIOY.mp3.xUSdFhL29
data
dropped
C:\Users\user\Documents\EOWRVPQCCS\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\EWZCVGNOWT.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\GIGIYTFFYT.mp3.xUSdFhL29
data
dropped
C:\Users\user\Documents\GIGIYTFFYT.pdf.xUSdFhL29
data
dropped
C:\Users\user\Documents\GIGIYTFFYT.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\GLTYDMDUST.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\JDDHMPCDUJ.pdf.xUSdFhL29
data
dropped
C:\Users\user\Documents\KLIZUSIQEN\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\LIJDSFKJZG.mp3.xUSdFhL29
data
dropped
C:\Users\user\Documents\Outlook Files\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\QCOILOQIKC.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\SNIPGPPREP\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\TQDFJHPUIU.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\TQDFJHPUIU\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\UNKRLCVOHV\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\VWDFPKGDUF\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\ZGGKNSUKOP.docx.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\Documents\ZGGKNSUKOP.pdf.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\GIGIYTFFYT.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\GLTYDMDUST.png.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\JDDHMPCDUJ.pdf.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\LIJDSFKJZG.mp3.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\ZGGKNSUKOP.docx.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\ZIPXYXWIOY.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZGGKNSUKOP\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Documents\ZIPXYXWIOY.jpg.xUSdFhL29
data
dropped
C:\Users\user\Documents\ZIPXYXWIOY.mp3.xUSdFhL29
data
dropped
C:\Users\user\Documents\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Downloads\DUUDTUBZFW.docx.xUSdFhL29
COM executable for DOS
dropped
C:\Users\user\Downloads\EIVQSAOTAQ.jpg.xUSdFhL29
data
dropped
C:\Users\user\Downloads\EIVQSAOTAQ.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Downloads\EOWRVPQCCS.docx.xUSdFhL29
data
dropped
C:\Users\user\Downloads\EOWRVPQCCS.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Downloads\EWZCVGNOWT.png.xUSdFhL29
data
dropped
C:\Users\user\Downloads\GIGIYTFFYT.mp3.xUSdFhL29
data
dropped
C:\Users\user\Downloads\GIGIYTFFYT.pdf.xUSdFhL29
data
dropped
C:\Users\user\Downloads\GIGIYTFFYT.xlsx.xUSdFhL29
data
dropped
C:\Users\user\Downloads\GLTYDMDUST.png.xUSdFhL29
data
dropped
C:\Users\user\Downloads\JDDHMPCDUJ.pdf.xUSdFhL29
data
dropped
C:\Users\user\Downloads\LIJDSFKJZG.mp3.xUSdFhL29
data
dropped
C:\Users\user\Downloads\QCOILOQIKC.png.xUSdFhL29
data
dropped
C:\Users\user\Downloads\TQDFJHPUIU.jpg.xUSdFhL29
data
dropped
C:\Users\user\Downloads\ZGGKNSUKOP.docx.xUSdFhL29
data
dropped
C:\Users\user\Downloads\ZGGKNSUKOP.pdf.xUSdFhL29
data
dropped
C:\Users\user\Downloads\ZIPXYXWIOY.jpg.xUSdFhL29
data
dropped
C:\Users\user\Downloads\ZIPXYXWIOY.mp3.xUSdFhL29
data
dropped
C:\Users\user\Downloads\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Favorites\Amazon.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Bing.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Facebook.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Google.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Links\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Favorites\Live.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\NYTimes.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Reddit.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Twitter.url.xUSdFhL29
OpenPGP Public Key
dropped
C:\Users\user\Favorites\Wikipedia.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\Youtube.url.xUSdFhL29
data
dropped
C:\Users\user\Favorites\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Links\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Music\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\OneDrive\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Pictures\Camera Roll\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Pictures\Saved Pictures\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Pictures\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Recent\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Saved Games\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Searches\winrt--{S-1-5-21-2246122658-3693405117-2476756634-1003}-.searchconnector-ms.xUSdFhL29
data
dropped
C:\Users\user\Searches\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\Videos\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\_curlrc.xUSdFhL29
data
dropped
C:\Users\user\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
C:\Windows\System32\spool\PRINTERS\00002.SPL
Microsoft OOXML
dropped
C:\xUSdFhL29.README.txt
ASCII text, with CRLF line terminators
dropped
\Device\Null
ASCII text, with CRLF line terminators
dropped
There are 1681 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\dllhost.exe
"C:\Users\user\Desktop\dllhost.exe"
malicious
C:\ProgramData\92D9.tmp
"C:\ProgramData\92D9.tmp"
malicious
C:\Windows\SysWOW64\cmd.exe
"C:\Windows\System32\cmd.exe" /C DEL /F /Q C:\PROGRA~3\92D9.tmp >> NUL
malicious
C:\Windows\splwow64.exe
C:\Windows\splwow64.exe 12288
C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE
/insertdoc "C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\{D8D07292-B10A-4D24-9495-A9C057D3ECEE}.xps" 133580332770710000
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
/tsr

URLs

Name
IP
Malicious
http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onionl
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionHC
unknown
malicious
https://tox.ch
unknown
malicious
http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onione&
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion
unknown
malicious
http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onional
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onion1
unknown
malicious
http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onionina
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionl
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionx
unknown
malicious
https://tox.chat
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onionalM
unknown
malicious
http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion
unknown
malicious
http://lockbitsupn2h6be2cnqpvncyhj4rgmnwn44633hnzzmtxdvjoqlp7yd.onioned
unknown
malicious
http://lockbitapt2yfbt7lchxejug47kmqvqqxvvjpqkmevv4l3azl3gy6pyd.onion22-4DB4-AC8E-4E1DDDE828FE_cw5n1
unknown
malicious
http://lockbitsupa7e3b4pkn4mgkgojrl5iqgx24clbzc4xm7i6jeetsia3qd.onion
unknown
malicious
https://chromeenterprise.google/policies/#BrowserSwitcherEnabled
unknown
https://support.google.com/chromebook?p=app_intent
unknown
https://support.google.com/chrome/answer/6098869
unknown
https://support.mozilla.org/products/firefoxgro.allizom.troppus.oGUCFCdKfd-E
unknown
http://www.unicode.org/copyright.html
unknown
https://chrome.google.com/webstore?hl=ru&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://chrome.google.com/webstore?hl=th
unknown
https://passwords.google.comGoogle
unknown
https://chrome.google.com/webstore?hl=hi&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
unknown
http://lockbitapt.uz
unknown
http://lockbitsupp.uz
unknown
https://photos.google.com/settings?referrer=CHROME_NTP
unknown
https://chromeenterprise.google/policies/#BrowserSwitcherExternalSitelistUrl
unknown
https://myactivity.google.com/
unknown
https://chromeenterprise.google/policies/#BrowserSwitcherExternalGreylistUrl
unknown
https://chrome.google.com/webstore?hl=uk
unknown
https://chromeenterprise.google/policies/#BrowserSwitcherUseIeSitelist
unknown
https://chromeenterprise.google/policies/#BrowserSwitcherUrlList
unknown
https://passwords.google.com
unknown
https://policies.google.com/
unknown
https://support.google.com/chrome/a/answer/9122284
unknown
https://chrome.google.com/webstore?hl=th&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://support.mozilla.org
unknown
https://chrome.google.com/webstore?hl=bn&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://chrome.google.com/webstore?hl=uk&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://chrome.google.com/webstore?hl=ur&category=theme81https://myactivity.google.com/myactivity/?u
unknown
https://chrome.google.com/webstore?hl=trK
unknown
https://chromeenterprise.google/policies/#BrowserSwitcherUrlGreylist
unknown
There are 35 hidden URLs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Control Panel\Desktop
WallPaper
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.xUSdFhL29
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\xUSdFhL29\DefaultIcon
NULL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFiles0000
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
RegFilesHash
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\AirSpaceChannel
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\EndpointMapper
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\FirstUXPerf-Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\ForwardedEvents
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\General Logging
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Intel-iaLPSS-GPIO/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Intel-iaLPSS2-GPIO2/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MedaFoundationVideoProc
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MediaFoundationMP4
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MediaFoundationPerformance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\MediaFoundationSrcPrefetch
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-AppV-Client/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-AppV-Client/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-AppV-Client/Virtual Applications
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-IEFRAME/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-JSDumpHeap/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-OneCore-Setup/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-PerfTrack-IEFRAME/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-Admin/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-Agent Driver/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-Agent Driver/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-Agent Driver/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-App Agent/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-User Experience Virtualization-App Agent/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-AppID/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application Server-Applications/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application Server-Applications/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application Server-Applications/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application Server-Applications/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application Server-Applications/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application-Experience/Program-Inventory
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application-Experience/Program-Inventory
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application-Experience/Program-Telemetry
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Application-Experience/Steps-Recorder
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-AppLocker/Packaged app-Deployment
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-AppLocker/Packaged app-Execution
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-AppXDeploymentServer/Restricted
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ASN1/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/CaptureMonitor
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/CaptureMonitor
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/GlitchDetection
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/PlaybackManager
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audio/PlaybackManager
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Audit/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Authentication User Interface/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BackgroundTransfer-ContentPrefetcher/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BitLocker-DrivePreparationTool/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BitLocker-DrivePreparationTool/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BitLocker-DrivePreparationTool/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BranchCacheSMB/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BTH-BTHPORT/HCI
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BTH-BTHPORT/L2CAP
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-BTH-BTHUSB/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Compat-Appraiser/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Compat-Appraiser/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-COMRuntime/Activations
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Containers-Wcifs/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Containers-Wcifs/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Containers-Wcnfs/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Containers-Wcnfs/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-CoreApplication/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Crypto-BCRYPT/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Crypto-RNG/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Crypto-RSAEnh/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DataIntegrityScan/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DataIntegrityScan/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Deduplication/Diagnostic
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Deduplication/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Deduplication/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Defrag-Core/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DeviceGuard/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DeviceGuard/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DiagCpl/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-AdvancedTaskManager/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-DPS/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-DPS/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-DPS/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-DPS/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-MSDE/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-PCW/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-PCW/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnosis-Scheduled/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Diagnostics-Performance/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Direct3D11/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DiskDiagnostic/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Documents/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Dot3MM/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DriverFrameworks-UserMode/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DucUpdateAgent/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DxgKrnl-Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DxgKrnl/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-DxgKrnl/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-EaseOfAccess/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-EDP-Audit-Regular/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-EDP-Audit-Regular/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Energy-Estimation-Engine/Trace
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-FileHistory-Engine/BackupLog
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-FileHistory-UI-Events/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-GroupPolicy/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Help/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-Hypervisor-Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-Hypervisor-Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-VID-Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Iphlpsvc/Trace
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-IPNAT/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-IPSEC-SRV/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kerberos/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-Acpi/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-AppCompat/General
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-AppCompat/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-ApphelpCache/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-ApphelpCache/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-Boot/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-Pdc/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-Pep/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-PnP/Configuration
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-PnP/Configuration
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-PnP/Configuration Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-PnP/Driver Watchdog
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-PnP/Driver Watchdog
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-WHEA/Errors
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Kernel-WHEA/Errors
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-LiveId/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Minstore/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Minstore/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Mobile-Broadband-Experience-SmsApi/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilot
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnostics
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnostics
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementService
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NcdAutoSetup/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NcdAutoSetup/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NCSI/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NCSI/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NDF-HelperClassDiscovery/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NDIS-PacketCapture/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NdisImPlatform/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-NetworkProvider/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Ntfs/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OfflineFiles/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OfflineFiles/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OfflineFiles/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OfflineFiles/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OfflineFiles/SyncLog
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OLEACC/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OLEACC/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OneBackup/Debug
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OneX/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OOBE-Machine-DUI/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OOBE-Machine-DUI/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-OOBE-Machine-Plugins-Wireless/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-PackageStateRoaming/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-PackageStateRoaming/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ParentalControls/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Partition/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Partition/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-PerceptionRuntime/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-Kernel-Mode-Transport/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RemoteDesktopServices-RemoteFX-VM-User-Mode-Transport/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RemoteDesktopServices-SessionServices/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RemoteDesktopServices-SessionServices/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Remotefs-Rdbss/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Remotefs-Rdbss/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Detector/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Resource-Exhaustion-Detector/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-RPC-Proxy/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Runtime-Graphics/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Runtime-Networking-BackgroundTransfer/Tracing
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Runtime-Networking/Tracing
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Runtime-Windows-Media/WinRTCaptureEngine
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Search-Core/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-EnterpriseData-FileRevocationManager/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-EnterpriseData-FileRevocationManager/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-ExchangeActiveSyncProvisioning/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-ExchangeActiveSyncProvisioning/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-IdentityStore/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Security-Mitigations/UserMode
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-ServiceReportingApi/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Servicing/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-Azure/Debug
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SettingSync-OneDrive/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Shell-Core/ActionCenter
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBClient/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SmbClient/Audit
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Audit
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Security
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBServer/Security
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBWitnessClient/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBWitnessClient/Informational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SMBWitnessClient/Informational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-SPB-ClassExtension/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-ATAPort/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-ClassPnP/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-ClassPnP/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-Tiering-IoHeat/Heat
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-Tiering/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storage-Tiering/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorageManagement/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorageManagement/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorageSpaces-Driver/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorageSpaces-SpaceManager/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorageSpaces-SpaceManager/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorDiag/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Store/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-StorPort/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storsvc/Diagnostic
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Storsvc/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Superfetch/Main
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Superfetch/PfApLog
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Superfetch/StoreLog
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Sysprep/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-TenantRestrictions/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-TerminalServices-RemoteConnectionManager/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-TerminalServices-RemoteConnectionManager/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-UAC-FileVirtualization/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-USB-USBPORT/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Windows Firewall With Advanced Security/ConnectionSecurity
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WinMDE/MDE
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WinML/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WinNat/Oper
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Winsrv/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Wired-AutoConfig/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Wordpad/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Wordpad/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/WHC
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WorkFolders/WHC
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Workplace Join/Admin
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Workplace Join/Admin
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WPD-API/Analytic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WPD-ClassInstaller/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WSC-SRV/Diagnostic
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-WWAN-SVC-Events/Operational
Enabled
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-XAudio2/Performance
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\OpenSSH/Debug
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\SystemEventsBroker
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\TabletPC_InputPanel_Channel/IHM
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\TimeBroker
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Windows Networking Vpn Plugin Platform/Operational
ChannelAccess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Windows Networking Vpn Plugin Platform/OperationalVerbose
ChannelAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5672
0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Resiliency\StartupItems
xa7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\onenote
Language
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\onenote
EcsRequestPending
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\onenote
SubscriptionCustomerLicenseInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{2DA16203-3F58-404F-839D-E4CDE7DD0DED}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{2DA16203-3F58-404F-839D-E4CDE7DD0DED}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{6D4B9C3E-CC05-493F-85E2-43D1006DF96A}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{6D4B9C3E-CC05-493F-85E2-43D1006DF96A}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}\TypeLib
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\TypeLib
Version
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\general
ConsecutiveBootCrashes
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\general
ConsecutiveEarlyCrashes
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\general
EDPLastRevokeCheckTime
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Options\Save
BackupFilenamePostfixStartSP1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Options\Save
BackupFilenamePostfixEndSP1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Options\Save
BackupFilenamePostfixEndRerepairSP1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\general
DateLastAttemptedOpeningLocalNotebooksOnBoot
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Options\Other
EnableMemoryTrayMenuItem
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Page Sync Status
PageSyncStatusPersistentData
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Page Sync Status
PageSyncStatusPersistentDataLastUpdateDate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\general
LastCacheFclRepairSuccessTime
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTimeOneNote
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTimeOneNote
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Experiment\onenote
BuildNumber
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote
Expires
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.2
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.3
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.4
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.5
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.6
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.7
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.8
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.9
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.10
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.11
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.12
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.13
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.14
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.15
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.17
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.18
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.19
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
1.21
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
VersionId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote
ETag
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote
DeferredConfigs
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote
ConfigIds
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Volatile
MsaDevice
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Options
UILanguageForQnote
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
LastRequest
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\RecentNotebooks
FOLDERID_Desktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\RecentNotebooks
FOLDERID_Documents
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Place MRU
FOLDERID_Desktop
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\onenote\Place MRU
FOLDERID_Documents
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
ForceCacheRefresh
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
OnceSucceeded
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
LastUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
NextUpdate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
Policy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA
Target
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA\AuthTrustedDomains\outlook-sdf.live.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA\AuthTrustedDomains\outlook-sdf.office.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA\AuthTrustedDomains\outlook.live.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_MSA\AuthTrustedDomains\outlook.office365.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID\AuthTrustedDomains\attachment-sdf.office.net
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID\AuthTrustedDomains\outlook-sdf.office.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID\AuthTrustedDomains\outlook.live.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID\AuthTrustedDomains\outlook.office.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_EXCHANGE_ORGID\AuthTrustedDomains\outlook.office365.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Height
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Policy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Provider
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA
Target
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url20x20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url24x24
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url40x40
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_MSA\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Height
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
Provider
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID
TokenIssuanceUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\AuthTrustedDomains\login.microsoftonline.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\Thumbnails
Url20x20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\Thumbnails
Url24x24
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\Thumbnails
Url40x40
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_2WAY_ORGID\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Height
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Policy
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Provider
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA
Target
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\AuthTrustedDomains\login.live.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url20x20
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url24x24
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url40x40
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_MSA\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
Height
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
Width
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
Provider
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID
TokenIssuanceUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID\AuthTrustedDomains\login.microsoftonline.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID\Thumbnails
Url24x24
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID\Thumbnails
Url40x40
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\FP_LINKEDIN_ORGID\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINT\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365MOUNTED_SHAREPOINTGROUP\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINT\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\O365_SHAREPOINTGROUP\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\OFFOPTIN_DOCSTORAGE_LIMITED\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
DefaultFolderRelativePath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
KeyTip
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINTGROUP\Metadata
Type
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
CapabilitiesMetadata
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Metadata
HideIfEmpty
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\ONPREM_SHAREPOINT_OTHER\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\AuthTrustedDomains\account.box-gov.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\AuthTrustedDomains\account.box.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\AuthTrustedDomains\api.box.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\AuthTrustedDomains\ent.box.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_BOX_2\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS\AuthTrustedDomains\citrixdata.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS\AuthTrustedDomains\sharefilestaging.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_CITRIX_PLUS\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS\AuthTrustedDomains\api.dropbox.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_DROPBOX_PLUS\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AuthBootStrapperUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\AuthTrustedDomains\integrations-prod.egnytegov.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\AuthTrustedDomains\integrations-staging.qa-egnytegov.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\AuthTrustedDomains\us-partner-integrations.egnyte.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_EGNYTE_PLUS\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AuthRedirectUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
ServiceUrl
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE
TokenIssuanceUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE\AuthTrustedDomains\accounts.google.com
Placeholder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE\Thumbnails
Url16x16
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE\Thumbnails
Url32x32
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE\Thumbnails
Url48x48
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AccountLimit
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AllowsRefreshTokenAccess
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AuthMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
Capabilities
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
ConnectMechanism
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
IsManaged
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
IsRemovable
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
ServiceOwner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
SortOrder
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
SupportsMultiple
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
SupportsNonRoaming
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AuthClientId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AuthScope
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
AuthorizationUri
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
Description
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
Name
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog\TP_GOOGLE_IMAP
ServiceId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-CH
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-GB
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-CH
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
en-GB
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common
SessionId
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5672
0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5672
0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\TypeLib\{F2A7EE29-8BF6-4a6d-83F1-098E366C709C}\1.0
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{C9590FA7-2132-47FB-9A78-AF0BF19AF4E6}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{2DA16203-3F58-404F-839D-E4CDE7DD0DED}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{2DA16203-3F58-404F-839D-E4CDE7DD0DED}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\TypeLib\{0EA692EE-BB50-4E3C-AEF0-356D91732725}\1.1
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{1D12BD3F-89B6-4077-AA2C-C9DC2BCA42F9}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{627EA7B4-95B5-4980-84C1-9D20DA4460B1}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{452AC71A-B655-4967-A208-A4CC39DD7949}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{6D4B9C3E-CC05-493F-85E2-43D1006DF96A}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{6D4B9C3E-CC05-493F-85E2-43D1006DF96A}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{8E8304B8-CBD1-44F8-B0E8-89C625B2002E}\TypeLib
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Wow6432Node\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\ProxyStubClsid32
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Classes\Interface\{E2E1511D-502D-4BD0-8B3A-8A89A05CDCAE}\TypeLib
NULL
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=8192&uilcid=1033&build=16.0.16827&crev=3\0
FilePath
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=8192&uilcid=1033&build=16.0.16827&crev=3\0
StartDate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Internet\WebServiceCache\AllUsers\officeclient.microsoft.com\config16--lcid=1033&syslcid=8192&uilcid=1033&build=16.0.16827&crev=3\0
EndDate
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote\ConfigContextData
ChunkCount
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ExperimentConfigs\Ecs\onenote
Expires
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5672
0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Property
0018000DDDFEBB86
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{2B379600-B42B-4FE9-A59C-A312FB934935}
DeviceTicket
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5672
0
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
RoamingLastSyncTimeOneNote
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\Roaming
RoamingLastWriteTimeOneNote
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\ServicesManagerCache\ServicesCatalog
CacheReady
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\000061091A0090400000000000F01FEC\Usage
OneNoteFilesIntl_1033
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\ClickToRun\REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00006109F00000000000000000F01FEC\Usage
OneNoteFiles
There are 844 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
CE1000
unkown
page execute read
malicious
11DE000
heap
page read and write
malicious
121B000
heap
page read and write
malicious
1246000
heap
page read and write
125C000
heap
page read and write
130A000
heap
page read and write
133B000
heap
page read and write
133A000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
150F000
heap
page read and write
325D000
heap
page read and write
14CE000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
1303000
heap
page read and write
1200000
heap
page read and write
45A1000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
12E7000
heap
page read and write
31D8000
heap
page read and write
31D7000
heap
page read and write
12F4000
heap
page read and write
126C000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
1244000
heap
page read and write
12F4000
heap
page read and write
405000
unkown
page write copy
13CD000
heap
page read and write
133A000
heap
page read and write
1318000
heap
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
123C000
heap
page read and write
45C1000
heap
page read and write
12F4000
heap
page read and write
133E000
heap
page read and write
1259000
heap
page read and write
41A0000
direct allocation
page read and write
125B000
heap
page read and write
31D6000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
1318000
heap
page read and write
1259000
heap
page read and write
126C000
heap
page read and write
12BD000
heap
page read and write
12FA000
heap
page read and write
1296000
heap
page read and write
1275000
heap
page read and write
1243000
heap
page read and write
1246000
heap
page read and write
127D000
heap
page read and write
31AE000
stack
page read and write
131A000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
31D2000
heap
page read and write
1290000
heap
page read and write
126D000
heap
page read and write
1313000
heap
page read and write
1271000
heap
page read and write
125C000
heap
page read and write
1318000
heap
page read and write
416F000
stack
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
1259000
heap
page read and write
126B000
heap
page read and write
133A000
heap
page read and write
4581000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12AD000
heap
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
125A000
heap
page read and write
400000
unkown
page readonly
1319000
heap
page read and write
31D1000
heap
page read and write
2B5E000
stack
page read and write
12FA000
heap
page read and write
11C4000
heap
page read and write
1319000
heap
page read and write
135C000
heap
page read and write
1245000
heap
page read and write
31D8000
heap
page read and write
9B000
stack
page read and write
11C4000
heap
page read and write
125B000
heap
page read and write
1207000
heap
page read and write
4622000
heap
page read and write
137C000
heap
page read and write
133B000
heap
page read and write
1259000
heap
page read and write
133A000
heap
page read and write
2F92000
heap
page read and write
1323000
heap
page read and write
12F9000
heap
page read and write
12FA000
heap
page read and write
1244000
heap
page read and write
127C000
heap
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
3271000
heap
page read and write
138F000
heap
page read and write
3271000
heap
page read and write
127C000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
12CC000
heap
page read and write
1242000
heap
page read and write
1213000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
1215000
heap
page read and write
11C4000
heap
page read and write
1259000
heap
page read and write
137C000
heap
page read and write
2DCF000
stack
page read and write
31D9000
heap
page read and write
129C000
heap
page read and write
12AC000
heap
page read and write
12FA000
heap
page read and write
1205000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
1259000
heap
page read and write
31D8000
heap
page read and write
1242000
heap
page read and write
125B000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
1318000
heap
page read and write
133A000
heap
page read and write
12C4000
heap
page read and write
129C000
heap
page read and write
130A000
heap
page read and write
131A000
heap
page read and write
126B000
heap
page read and write
12F7000
heap
page read and write
132A000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
130A000
heap
page read and write
133C000
heap
page read and write
2F71000
heap
page read and write
125B000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12E4000
heap
page read and write
12FA000
heap
page read and write
12AC000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
1295000
heap
page read and write
1313000
heap
page read and write
133A000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
31D4000
heap
page read and write
123F000
heap
page read and write
44C0000
heap
page read and write
34CF000
stack
page read and write
1244000
heap
page read and write
1318000
heap
page read and write
12FA000
heap
page read and write
31DE000
heap
page read and write
138C000
heap
page read and write
1318000
heap
page read and write
31DB000
heap
page read and write
125B000
heap
page read and write
31D1000
heap
page read and write
DF0000
heap
page execute and read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
31D8000
heap
page read and write
125B000
heap
page read and write
12FC000
heap
page read and write
12FA000
heap
page read and write
1259000
heap
page read and write
1313000
heap
page read and write
4602000
heap
page read and write
11C4000
heap
page read and write
132C000
heap
page read and write
131A000
heap
page read and write
135C000
heap
page read and write
1242000
heap
page read and write
318C000
stack
page read and write
1213000
heap
page read and write
1323000
heap
page read and write
12FA000
heap
page read and write
D06000
unkown
page write copy
133A000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
12AC000
heap
page read and write
12FA000
heap
page read and write
26D3000
heap
page execute and read and write
1237000
heap
page read and write
133A000
heap
page read and write
31DC000
heap
page read and write
1318000
heap
page read and write
2F71000
heap
page read and write
2F0F000
stack
page read and write
12FA000
heap
page read and write
14EE000
heap
page read and write
1248000
heap
page read and write
130A000
heap
page read and write
1248000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
124B000
heap
page read and write
130A000
heap
page read and write
133B000
heap
page read and write
1244000
heap
page read and write
4602000
heap
page read and write
138C000
heap
page read and write
12CD000
heap
page read and write
1259000
heap
page read and write
12F9000
heap
page read and write
126C000
heap
page read and write
1248000
heap
page read and write
47C4000
heap
page read and write
135C000
heap
page read and write
137C000
heap
page read and write
1328000
heap
page read and write
127C000
heap
page read and write
2F4E000
stack
page read and write
2F72000
heap
page read and write
1244000
heap
page read and write
13AC000
heap
page read and write
129C000
heap
page read and write
11C4000
heap
page read and write
13CD000
heap
page read and write
133A000
heap
page read and write
47C2000
heap
page read and write
156F000
heap
page read and write
1313000
heap
page read and write
31DE000
heap
page read and write
12F4000
heap
page read and write
12FA000
heap
page read and write
13FC000
heap
page read and write
31D5000
heap
page read and write
1244000
heap
page read and write
1242000
heap
page read and write
125C000
heap
page read and write
150F000
heap
page read and write
1259000
heap
page read and write
12AC000
heap
page read and write
30C5000
heap
page read and write
1248000
heap
page read and write
1248000
heap
page read and write
131A000
heap
page read and write
12FA000
heap
page read and write
17CE000
stack
page read and write
1318000
heap
page read and write
133C000
heap
page read and write
11C4000
heap
page read and write
130A000
heap
page read and write
129D000
heap
page read and write
12FA000
heap
page read and write
123D000
heap
page read and write
12FA000
heap
page read and write
31D8000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
11C4000
heap
page read and write
406000
unkown
page readonly
19B000
stack
page read and write
4561000
heap
page read and write
1338000
heap
page read and write
1385000
heap
page read and write
12FA000
heap
page read and write
31DA000
heap
page read and write
125C000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
2BC0000
heap
page read and write
12FA000
heap
page read and write
126C000
heap
page read and write
1328000
heap
page read and write
125B000
heap
page read and write
1235000
heap
page read and write
125C000
heap
page read and write
126C000
heap
page read and write
120A000
heap
page read and write
12C4000
heap
page read and write
1248000
heap
page read and write
12FA000
heap
page read and write
26D0000
heap
page execute and read and write
131A000
heap
page read and write
900000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
1244000
heap
page read and write
126C000
heap
page read and write
12FA000
heap
page read and write
12AC000
heap
page read and write
125B000
heap
page read and write
11DA000
heap
page read and write
127C000
heap
page read and write
4500000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1240000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
138C000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
1313000
heap
page read and write
12E4000
heap
page read and write
CDD000
stack
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
125B000
heap
page read and write
1313000
heap
page read and write
1246000
heap
page read and write
133C000
heap
page read and write
130A000
heap
page read and write
152F000
heap
page read and write
45E2000
heap
page read and write
31D9000
heap
page read and write
13AC000
heap
page read and write
31DA000
heap
page read and write
CFB000
unkown
page write copy
12F5000
heap
page read and write
11C4000
heap
page read and write
7FDC0000
direct allocation
page execute and read and write
12FA000
heap
page read and write
126C000
heap
page read and write
12FA000
heap
page read and write
137C000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
3143000
heap
page execute and read and write
1249000
heap
page read and write
1318000
heap
page read and write
12AC000
heap
page read and write
1242000
heap
page read and write
124B000
heap
page read and write
1248000
heap
page read and write
2F9F000
heap
page read and write
130A000
heap
page read and write
125C000
heap
page read and write
125A000
heap
page read and write
126B000
heap
page read and write
1248000
heap
page read and write
125A000
heap
page read and write
1236000
heap
page read and write
12FA000
heap
page read and write
1245000
heap
page read and write
12FA000
heap
page read and write
133E000
heap
page read and write
24A0000
heap
page read and write
2F70000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
2B9E000
stack
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
12BD000
heap
page read and write
1246000
heap
page read and write
130A000
heap
page read and write
11C4000
heap
page read and write
31D5000
heap
page read and write
12FA000
heap
page read and write
1590000
heap
page read and write
1313000
heap
page read and write
130A000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
1275000
heap
page read and write
31D8000
heap
page read and write
12F4000
heap
page read and write
126C000
heap
page read and write
31DD000
heap
page read and write
125B000
heap
page read and write
1244000
heap
page read and write
47C4000
heap
page read and write
12FA000
heap
page read and write
11FB000
heap
page read and write
125B000
heap
page read and write
129C000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
11C4000
heap
page read and write
12FA000
heap
page read and write
12D8000
heap
page read and write
135C000
heap
page read and write
12FA000
heap
page read and write
1318000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
126C000
heap
page read and write
31D0000
heap
page read and write
133B000
heap
page read and write
45E2000
heap
page read and write
3EEF000
stack
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
31DD000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
123E000
heap
page read and write
2F71000
heap
page read and write
A4F000
stack
page read and write
139C000
heap
page read and write
126B000
heap
page read and write
1342000
heap
page read and write
31DE000
heap
page read and write
1242000
heap
page read and write
123F000
heap
page read and write
A8E000
stack
page read and write
2E0E000
stack
page read and write
1211000
heap
page read and write
130A000
heap
page read and write
1209000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
2F9E000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
4561000
heap
page read and write
12F4000
heap
page read and write
125B000
heap
page read and write
420000
heap
page read and write
125B000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
11C4000
heap
page read and write
1242000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
12FE000
heap
page read and write
12D8000
heap
page read and write
1323000
heap
page read and write
3110000
heap
page read and write
1328000
heap
page read and write
133C000
heap
page read and write
133A000
heap
page read and write
C2C000
stack
page read and write
113E000
stack
page read and write
11C4000
heap
page read and write
31DD000
heap
page read and write
133C000
heap
page read and write
CFA000
unkown
page readonly
13CC000
heap
page read and write
1337000
heap
page read and write
1246000
heap
page read and write
137C000
heap
page read and write
133A000
heap
page read and write
125C000
heap
page read and write
125C000
heap
page read and write
125C000
heap
page read and write
31D7000
heap
page read and write
1234000
heap
page read and write
14CE000
heap
page read and write
1248000
heap
page read and write
4520000
heap
page read and write
133C000
heap
page read and write
12D4000
heap
page read and write
125C000
heap
page read and write
1244000
heap
page read and write
47C5000
heap
page read and write
125C000
heap
page read and write
1246000
heap
page read and write
132B000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
1313000
heap
page read and write
126D000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
130E000
heap
page read and write
139C000
heap
page read and write
12FA000
heap
page read and write
133B000
heap
page read and write
146E000
heap
page read and write
133A000
heap
page read and write
12AC000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
1248000
heap
page read and write
1242000
heap
page read and write
1310000
heap
page read and write
31D8000
heap
page read and write
1246000
heap
page read and write
1200000
heap
page read and write
125C000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
31D3000
heap
page read and write
31C0000
heap
page read and write
1249000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1245000
heap
page read and write
2F71000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
133C000
heap
page read and write
31DD000
heap
page read and write
269E000
stack
page read and write
133C000
heap
page read and write
4720000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
1244000
heap
page read and write
1244000
heap
page read and write
129C000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
125C000
heap
page read and write
1333000
heap
page read and write
12FA000
heap
page read and write
12B8000
heap
page read and write
1242000
heap
page read and write
13AC000
heap
page read and write
132C000
heap
page read and write
138E000
heap
page read and write
13CD000
heap
page read and write
129D000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
1242000
heap
page read and write
1338000
heap
page read and write
154F000
heap
page read and write
12FA000
heap
page read and write
31D9000
heap
page read and write
12FA000
heap
page read and write
1318000
heap
page read and write
125A000
heap
page read and write
129D000
heap
page read and write
133C000
heap
page read and write
133A000
heap
page read and write
1248000
heap
page read and write
402F000
stack
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
133C000
heap
page read and write
1242000
heap
page read and write
12F4000
heap
page read and write
12FA000
heap
page read and write
11C4000
heap
page read and write
1259000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
126C000
heap
page read and write
1242000
heap
page read and write
4700000
heap
page read and write
1259000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
12CD000
heap
page read and write
130A000
heap
page read and write
31D1000
heap
page read and write
1242000
heap
page read and write
1238000
heap
page read and write
1210000
heap
page read and write
31D4000
heap
page read and write
133A000
heap
page read and write
125C000
heap
page read and write
126B000
heap
page read and write
133A000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
1280000
heap
page read and write
43E000
heap
page read and write
12FA000
heap
page read and write
31DD000
heap
page read and write
12FA000
heap
page read and write
2F71000
heap
page read and write
125C000
heap
page read and write
129C000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
128D000
heap
page read and write
1242000
heap
page read and write
11C4000
heap
page read and write
12FA000
heap
page read and write
133B000
heap
page read and write
31D8000
heap
page read and write
133C000
heap
page read and write
3140000
heap
page execute and read and write
126C000
heap
page read and write
126C000
heap
page read and write
1246000
heap
page read and write
31D4000
heap
page read and write
12AC000
heap
page read and write
12F4000
heap
page read and write
121F000
heap
page read and write
131A000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
1313000
heap
page read and write
94E000
stack
page read and write
1248000
heap
page read and write
1246000
heap
page read and write
12FA000
heap
page read and write
126C000
heap
page read and write
125C000
heap
page read and write
1211000
heap
page read and write
126C000
heap
page read and write
46E0000
heap
page read and write
138C000
heap
page read and write
1310000
heap
page read and write
133B000
heap
page read and write
24B0000
direct allocation
page read and write
12F4000
heap
page read and write
12FA000
heap
page read and write
1342000
heap
page read and write
1246000
heap
page read and write
1378000
heap
page read and write
126B000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12F9000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
1323000
heap
page read and write
1315000
heap
page read and write
1259000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
47A1000
heap
page read and write
133A000
heap
page read and write
12F6000
heap
page read and write
130A000
heap
page read and write
135C000
heap
page read and write
1248000
heap
page read and write
1244000
heap
page read and write
117E000
stack
page read and write
125B000
heap
page read and write
13BC000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
7FE40000
direct allocation
page execute and read and write
31DD000
heap
page read and write
31DD000
heap
page read and write
121B000
heap
page read and write
123A000
heap
page read and write
130A000
heap
page read and write
1259000
heap
page read and write
13AC000
heap
page read and write
12FA000
heap
page read and write
12AC000
heap
page read and write
125B000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
130A000
heap
page read and write
3251000
heap
page read and write
31D5000
heap
page read and write
12FA000
heap
page read and write
31DE000
heap
page read and write
130A000
heap
page read and write
137C000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
31D9000
heap
page read and write
133C000
heap
page read and write
1246000
heap
page read and write
1248000
heap
page read and write
405000
unkown
page read and write
137C000
heap
page read and write
31D5000
heap
page read and write
1245000
heap
page read and write
12F8000
heap
page read and write
46C0000
heap
page read and write
11C4000
heap
page read and write
1242000
heap
page read and write
1249000
heap
page read and write
31D4000
heap
page read and write
24E0000
heap
page read and write
133B000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1219000
heap
page read and write
1242000
heap
page read and write
123E000
heap
page read and write
31DA000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
11FB000
heap
page read and write
12EF000
heap
page read and write
125C000
heap
page read and write
133C000
heap
page read and write
1259000
heap
page read and write
12FA000
heap
page read and write
1318000
heap
page read and write
12F7000
heap
page read and write
133A000
heap
page read and write
2F71000
heap
page read and write
1240000
heap
page read and write
1313000
heap
page read and write
131A000
heap
page read and write
1242000
heap
page read and write
137C000
heap
page read and write
12FA000
heap
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
CFA000
unkown
page readonly
11C4000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
133B000
heap
page read and write
128D000
heap
page read and write
31DC000
heap
page read and write
130A000
heap
page read and write
4602000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
1310000
heap
page read and write
1249000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
129D000
heap
page read and write
12AC000
heap
page read and write
11C4000
heap
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
1334000
heap
page read and write
31DA000
heap
page read and write
125C000
heap
page read and write
137C000
heap
page read and write
1298000
heap
page read and write
1328000
heap
page read and write
133B000
heap
page read and write
130A000
heap
page read and write
137C000
heap
page read and write
45A1000
heap
page read and write
130A000
heap
page read and write
1244000
heap
page read and write
31D4000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12A4000
heap
page read and write
133C000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
127D000
heap
page read and write
1338000
heap
page read and write
125B000
heap
page read and write
12E4000
heap
page read and write
137C000
heap
page read and write
12FA000
heap
page read and write
11C4000
heap
page read and write
133C000
heap
page read and write
130A000
heap
page read and write
1259000
heap
page read and write
1F0000
heap
page read and write
31D8000
heap
page read and write
12FA000
heap
page read and write
129C000
heap
page read and write
41A0000
direct allocation
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
11C0000
heap
page read and write
16CE000
stack
page read and write
2CCF000
stack
page read and write
12FA000
heap
page read and write
137C000
heap
page read and write
12E4000
heap
page read and write
31DB000
heap
page read and write
31D8000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
123E000
heap
page read and write
47C1000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
30D0000
direct allocation
page read and write
31DC000
heap
page read and write
125C000
heap
page read and write
12A4000
heap
page read and write
1318000
heap
page read and write
129D000
heap
page read and write
12FA000
heap
page read and write
31D6000
heap
page read and write
132A000
heap
page read and write
133B000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
125B000
heap
page read and write
12F5000
heap
page read and write
11D0000
heap
page read and write
3250000
heap
page read and write
12FA000
heap
page read and write
BCE000
stack
page read and write
47A1000
heap
page read and write
1313000
heap
page read and write
1280000
heap
page read and write
31D0000
heap
page read and write
120E000
heap
page read and write
1242000
heap
page read and write
1242000
heap
page read and write
13ED000
heap
page read and write
125B000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
2FB1000
heap
page read and write
1312000
heap
page read and write
404000
unkown
page readonly
12FA000
heap
page read and write
47A1000
heap
page read and write
12FA000
heap
page read and write
47C1000
heap
page read and write
125C000
heap
page read and write
1313000
heap
page read and write
125B000
heap
page read and write
1249000
heap
page read and write
1248000
heap
page read and write
137C000
heap
page read and write
123B000
heap
page read and write
126C000
heap
page read and write
1243000
heap
page read and write
12AC000
heap
page read and write
1244000
heap
page read and write
43A000
heap
page read and write
1244000
heap
page read and write
133A000
heap
page read and write
130A000
heap
page read and write
127C000
heap
page read and write
1242000
heap
page read and write
12BE000
heap
page read and write
12BD000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
31D2000
heap
page read and write
125C000
heap
page read and write
31DC000
heap
page read and write
125C000
heap
page read and write
1242000
heap
page read and write
126C000
heap
page read and write
1242000
heap
page read and write
126C000
heap
page read and write
1259000
heap
page read and write
1238000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
125B000
heap
page read and write
133A000
heap
page read and write
31D9000
heap
page read and write
12FA000
heap
page read and write
1246000
heap
page read and write
152F000
heap
page read and write
133B000
heap
page read and write
12FA000
heap
page read and write
31DB000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
1328000
heap
page read and write
1328000
heap
page read and write
12FA000
heap
page read and write
31D8000
heap
page read and write
13ED000
heap
page read and write
31D0000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
12F7000
heap
page read and write
2F80000
heap
page read and write
1246000
heap
page read and write
308C000
stack
page read and write
12FA000
heap
page read and write
125B000
heap
page read and write
31D2000
heap
page read and write
1248000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
31DD000
heap
page read and write
12C4000
heap
page read and write
12FA000
heap
page read and write
12F7000
heap
page read and write
1259000
heap
page read and write
125C000
heap
page read and write
2F71000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
31D5000
heap
page read and write
1224000
heap
page read and write
2F99000
heap
page read and write
31D7000
heap
page read and write
11C4000
heap
page read and write
12FA000
heap
page read and write
4781000
heap
page read and write
3DEE000
stack
page read and write
130A000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
1323000
heap
page read and write
150F000
heap
page read and write
12FA000
heap
page read and write
127D000
heap
page read and write
133A000
heap
page read and write
125B000
heap
page read and write
31D7000
heap
page read and write
1259000
heap
page read and write
31DF000
heap
page read and write
2F9F000
heap
page read and write
12FA000
heap
page read and write
C80000
heap
page read and write
133A000
heap
page read and write
12C4000
heap
page read and write
12FA000
heap
page read and write
12F8000
heap
page read and write
133A000
heap
page read and write
30C0000
heap
page read and write
1242000
heap
page read and write
1244000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
2F71000
heap
page read and write
12AC000
heap
page read and write
131C000
heap
page read and write
D04000
unkown
page read and write
1245000
heap
page read and write
430000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
127B000
heap
page read and write
133A000
heap
page read and write
139C000
heap
page read and write
12FA000
heap
page read and write
2B1E000
stack
page read and write
128D000
heap
page read and write
138C000
heap
page read and write
401000
unkown
page execute read
12FA000
heap
page read and write
31DE000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
12E4000
heap
page read and write
126C000
heap
page read and write
130A000
heap
page read and write
1246000
heap
page read and write
133B000
heap
page read and write
31DC000
heap
page read and write
126C000
heap
page read and write
1242000
heap
page read and write
1313000
heap
page read and write
1259000
heap
page read and write
138F000
heap
page read and write
133A000
heap
page read and write
1242000
heap
page read and write
31DC000
heap
page read and write
12FA000
heap
page read and write
14AE000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
31D2000
heap
page read and write
3F2E000
stack
page read and write
126C000
heap
page read and write
1248000
heap
page read and write
12FA000
heap
page read and write
1249000
heap
page read and write
2F71000
heap
page read and write
1318000
heap
page read and write
1234000
heap
page read and write
133A000
heap
page read and write
133A000
heap
page read and write
123E000
heap
page read and write
122E000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
126C000
heap
page read and write
2F9F000
heap
page read and write
1242000
heap
page read and write
1245000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
12FA000
heap
page read and write
125A000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
121B000
heap
page read and write
123F000
heap
page read and write
12FA000
heap
page read and write
7FE20000
direct allocation
page execute and read and write
B2B000
stack
page read and write
133A000
heap
page read and write
31D3000
heap
page read and write
131A000
heap
page read and write
1201000
heap
page read and write
126C000
heap
page read and write
130A000
heap
page read and write
133A000
heap
page read and write
12F8000
heap
page read and write
1236000
heap
page read and write
12FA000
heap
page read and write
31DF000
heap
page read and write
133A000
heap
page read and write
12F4000
heap
page read and write
135C000
heap
page read and write
1245000
heap
page read and write
125C000
heap
page read and write
3130000
direct allocation
page read and write
12FA000
heap
page read and write
137D000
heap
page read and write
CE0000
unkown
page readonly
1246000
heap
page read and write
133A000
heap
page read and write
1203000
heap
page read and write
130A000
heap
page read and write
1314000
heap
page read and write
1248000
heap
page read and write
C90000
heap
page read and write
12FA000
heap
page read and write
304F000
stack
page read and write
12FA000
heap
page read and write
1F5000
heap
page read and write
31D0000
heap
page read and write
133A000
heap
page read and write
12BD000
heap
page read and write
12F9000
heap
page read and write
131A000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
31D8000
heap
page read and write
31D5000
heap
page read and write
12FA000
heap
page read and write
31DF000
heap
page read and write
3291000
heap
page read and write
137C000
heap
page read and write
12FC000
heap
page read and write
12FA000
heap
page read and write
404000
unkown
page readonly
10FE000
stack
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
1244000
heap
page read and write
31DA000
heap
page read and write
1248000
heap
page read and write
12FA000
heap
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
31D1000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
1245000
heap
page read and write
31DC000
heap
page read and write
125C000
heap
page read and write
125A000
heap
page read and write
12FA000
heap
page read and write
1200000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
139C000
heap
page read and write
11C4000
heap
page read and write
2480000
heap
page execute and read and write
4741000
heap
page read and write
31D0000
heap
page read and write
12FA000
heap
page read and write
31DC000
heap
page read and write
12FA000
heap
page read and write
31D3000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
126C000
heap
page read and write
126C000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
31D4000
heap
page read and write
1248000
heap
page read and write
12FA000
heap
page read and write
463000
heap
page read and write
133C000
heap
page read and write
139C000
heap
page read and write
1259000
heap
page read and write
152F000
heap
page read and write
D07000
unkown
page readonly
126C000
heap
page read and write
12DC000
heap
page read and write
31D9000
heap
page read and write
12FA000
heap
page read and write
3251000
heap
page read and write
1259000
heap
page read and write
12FA000
heap
page read and write
406E000
stack
page read and write
1242000
heap
page read and write
126C000
heap
page read and write
130A000
heap
page read and write
1318000
heap
page read and write
12FA000
heap
page read and write
7FE10000
direct allocation
page read and write
125C000
heap
page read and write
123B000
heap
page read and write
133B000
heap
page read and write
1313000
heap
page read and write
133A000
heap
page read and write
11FE000
heap
page read and write
1313000
heap
page read and write
2F71000
heap
page read and write
1244000
heap
page read and write
130A000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133B000
heap
page read and write
31D2000
heap
page read and write
1242000
heap
page read and write
133A000
heap
page read and write
1323000
heap
page read and write
125B000
heap
page read and write
1323000
heap
page read and write
1318000
heap
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
12E4000
heap
page read and write
137D000
heap
page read and write
12FA000
heap
page read and write
125B000
heap
page read and write
31DF000
heap
page read and write
1313000
heap
page read and write
126C000
heap
page read and write
2570000
heap
page read and write
1259000
heap
page read and write
12FA000
heap
page read and write
1306000
heap
page read and write
125C000
heap
page read and write
12CA000
heap
page read and write
130A000
heap
page read and write
130A000
heap
page read and write
13ED000
heap
page read and write
31DE000
heap
page read and write
126C000
heap
page read and write
12FA000
heap
page read and write
139C000
heap
page read and write
1318000
heap
page read and write
138C000
heap
page read and write
12FA000
heap
page read and write
31D0000
heap
page read and write
1259000
heap
page read and write
401000
unkown
page execute and read and write
12FA000
heap
page read and write
131F000
heap
page read and write
133B000
heap
page read and write
1248000
heap
page read and write
12F9000
heap
page read and write
13ED000
heap
page read and write
1241000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
4683000
heap
page read and write
126C000
heap
page read and write
1328000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
12FA000
heap
page read and write
125A000
heap
page read and write
1241000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
31D1000
heap
page read and write
125C000
heap
page read and write
41B6000
heap
page read and write
130A000
heap
page read and write
15B0000
heap
page read and write
1259000
heap
page read and write
12FA000
heap
page read and write
1313000
heap
page read and write
12FA000
heap
page read and write
1244000
heap
page read and write
133C000
heap
page read and write
1246000
heap
page read and write
12FA000
heap
page read and write
133A000
heap
page read and write
CCF000
stack
page read and write
1243000
heap
page read and write
12F9000
heap
page read and write
1242000
heap
page read and write
31DA000
heap
page read and write
130A000
heap
page read and write
1249000
heap
page read and write
12F4000
heap
page read and write
133A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
2F81000
heap
page read and write
11B0000
heap
page read and write
1363000
heap
page read and write
130A000
heap
page read and write
1242000
heap
page read and write
B8F000
stack
page read and write
1318000
heap
page read and write
11C4000
heap
page read and write
47C1000
heap
page read and write
120C000
heap
page read and write
31D8000
heap
page read and write
125C000
heap
page read and write
31DC000
heap
page read and write
12C4000
heap
page read and write
31D5000
heap
page read and write
125A000
heap
page read and write
3291000
heap
page read and write
1259000
heap
page read and write
126B000
heap
page read and write
12FC000
heap
page read and write
7FE30000
direct allocation
page read and write
1323000
heap
page read and write
125B000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
133C000
heap
page read and write
130A000
heap
page read and write
12F4000
heap
page read and write
11C4000
heap
page read and write
1246000
heap
page read and write
1316000
heap
page read and write
129D000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1305000
heap
page read and write
126C000
heap
page read and write
1329000
heap
page read and write
1248000
heap
page read and write
12F4000
heap
page read and write
2F71000
heap
page read and write
137C000
heap
page read and write
126C000
heap
page read and write
126B000
heap
page read and write
12FA000
heap
page read and write
124D000
heap
page read and write
12FA000
heap
page read and write
125C000
heap
page read and write
12CD000
heap
page read and write
133A000
heap
page read and write
487000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1242000
heap
page read and write
12FA000
heap
page read and write
4642000
heap
page read and write
133C000
heap
page read and write
1244000
heap
page read and write
12F4000
heap
page read and write
129C000
heap
page read and write
12F7000
heap
page read and write
125C000
heap
page read and write
125B000
heap
page read and write
126C000
heap
page read and write
133A000
heap
page read and write
122E000
heap
page read and write
1246000
heap
page read and write
125B000
heap
page read and write
133A000
heap
page read and write
1244000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
12FA000
heap
page read and write
12FA000
heap
page read and write
1248000
heap
page read and write
31DD000
heap
page read and write
1590000
heap
page read and write
11C4000
heap
page read and write
129D000
heap
page read and write
1241000
heap
page read and write
12F9000
heap
page read and write
125B000
heap
page read and write
125C000
heap
page read and write
45E2000
heap
page read and write
12FA000
heap
page read and write
130A000
heap
page read and write
130A000
heap
page read and write
1259000
heap
page read and write
1248000
heap
page read and write
133C000
heap
page read and write
12DD000
heap
page read and write
There are 1324 hidden memdumps, click here to show them.