IOC Report
831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe

loading gif

Files

File Path
Type
Category
Malicious
831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
initial sample
malicious
C:\Users\Public\Libraries\(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
dropped
malicious
C:\Users\user\AppData\Local\Temp\31PgCcUBGPwV6NnfvXczXQ1.zip
Zip archive data, at least v2.0 to extract, compression method=deflate
modified
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528
Mozilla lz4 compressed data, originally 3725 bytes
dropped
malicious
C:\Users\user\AppData\Local\Temp\qejgAV31ox5GsAcJ2HC9KPd.zip
Zip archive data, at least v2.0 to extract, compression method=deflate
modified
malicious
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2ce60361-e872-41fb-bae7-eec2f580d4fb}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2ce60361-e872-41fb-bae7-eec2f580d4fb}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{400a70c4-3e12-4cbe-805a-2dc7c298a033}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{400a70c4-3e12-4cbe-805a-2dc7c298a033}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\AlternateServices.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\SiteSecurityServiceState.txt
CSV text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\pkcs11.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\previous.jsonlz4
Mozilla lz4 compressed data, originally 3725 bytes
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Files\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\sessionstore-backups\upgrade.jsonlz4-20230927232528
Mozilla lz4 compressed data, originally 3725 bytes
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\Content.IE5\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Microsoft\Windows\Temporary Internet Files\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeHpbNlo3JVv_6\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{16b4cf2a-868f-4ec8-93d1-22a741a69582}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{9a386491-5394-47a0-a408-e4e3a9d60139}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.0.filtertrie.intermediate.txt
Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{a2b8def6-bc9d-4428-9584-a8d7c21735f8}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2ce60361-e872-41fb-bae7-eec2f580d4fb}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{2ce60361-e872-41fb-bae7-eec2f580d4fb}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{400a70c4-3e12-4cbe-805a-2dc7c298a033}\0.1.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Settings_{400a70c4-3e12-4cbe-805a-2dc7c298a033}\0.2.filtertrie.intermediate.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Files\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Mini-Wallet\miniwallet.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Notification\notification_fast.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Tokenized-Card\tokenized-card.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\Wallet-Checkout\wallet-drawer.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\pwaunauth-9d8bc214ac[1].css
ASCII text, with very long lines (5259), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-apps-image-46596a6856[1].png
PNG image data, 588 x 146, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\AC\INetCache\CAMZ26JJ\unauth-checkmark-image-1999f0bf81[1].png
PNG image data, 22 x 17, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{f2609905-bc23-4c47-8645-cbcf38bc7d2c}\settingsglobals.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\StartUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\TempState\TileCache_100_3_PNGEncoded_Header.bin
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\CURRENT
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\MANIFEST-000001
OpenPGP Secret Key
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\EADPData Component\4.0.2.33\data.txt
ASCII text, with very long lines (65536), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\bnpl\bnpl.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\crypto.bundle.js
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\driver-signature.txt
ASCII text, with very long lines (14343), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\hub-signature.txt
ASCII text, with very long lines (975), with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\vendor.bundle.js.LICENSE.txt
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Edge Wallet\116.16385.16360.19\wallet-crypto.html
HTML document, ASCII text, with very long lines (560)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\TrustTokenKeyCommitments\2023.9.4.1\keys.json
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\FGDLZ049\ReportOwner[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\W1DLB4AP\ProcessMAU[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\1527c705-839a-4832-9118-54d4Bd6a0c89_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\E2A4F912-2574-4A75-9BB0-0D023378592B_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.549981C3F5F10_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.AsyncTextService_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.CredDialogHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ECApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.GetHelp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.HEIFImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MSPaint_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Microsoft3DViewer_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdgeDevToolsClient_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\User.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\SystemAppData\Helium\UserClasses.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.MixedReality.Portal_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ScreenSketch_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.StorePurchaseApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.VP9VideoExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Wallet_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebMediaExtensions_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WebpImageExtension_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Win32WebViewHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Apprep.ChxApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CallingShellApp_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CapturePicker_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.NarratorQuickStart_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkCaptivePortal_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.OOBENetworkConnectionFlow_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PeopleExperienceHost_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.PinningConfirmationDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\TempState\CortanaUnifiedTileModelCache.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.SecureAssessmentBrowser_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Windows.XGpuEjectDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsFeedbackHub_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.Xbox.TCUI_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxGameOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxIdentityProvider_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.XboxSpeechToTextOverlay_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.YourPhone_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.CBSPreview_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\c5e2524a-ea46-4f67-841f-6a9465d9d515_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Edge\User Data\Crashpad\throttle_store.dat
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Internet Explorer\brndlog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Office\Features\1-7FeatureCache.txt
data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat
JSON data
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Vault\UserProfileRoaming\Latest.dat
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\ATCVA5TX\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Microsoft\Windows\INetCache\IE\BEDT2L3A\Rdr[1].txt
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Packages\NcsiUwpApp_8wekyb3d8bbwe\Settings\settings.dat
MS Windows registry file, NT/2000 or above
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobeoXPwUyynlHg5\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\Cookies\Chrome_Default.txt
ASCII text, with very long lines (369), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\Files\AppData\Local\Temp\scoped_dir5952_991612011\CRX_INSTALL\sw_modules\googleQueryAnalyzer.js
ASCII text, with very long lines (1778)
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\History\Firefox_fu7wner3.default-release.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\information.txt
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\adobepbqnrM0s9U5u\passwords.txt
Unicode text, UTF-8 text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\02zdBXl47cvzHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\02zdBXl47cvzcookies.sqlite
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\2jQJv37iJ0lzCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\3b6N2Xdh3CYwWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\3b6N2Xdh3CYwplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\8ghN89CsjOW1Login Data For Account
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\D87fZN3R3jFeWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\D87fZN3R3jFeplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\Ei8DrAmaYu9KLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\IWPfiAXUTJTSHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\KvHrxJ77cmUgLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\QdX9ITDLyCRBWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\UPG2LoPXwc7OWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\ZunTSaNJLBVfWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\o0qT3dWYBP7ZHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\oOPEmFmu_xsJCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 5, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 5
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\pSE1jchbiT9aHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidiHpbNlo3JVv_6\suOrwW4ZcUbjWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\02zdBXl47cvzHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\02zdBXl47cvzcookies.sqlite
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\2jQJv37iJ0lzCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\3b6N2Xdh3CYwWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\3b6N2Xdh3CYwplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\8ghN89CsjOW1Login Data For Account
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\D87fZN3R3jFeWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\D87fZN3R3jFeplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\Ei8DrAmaYu9KLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\IWPfiAXUTJTSHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\KvHrxJ77cmUgLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\QdX9ITDLyCRBWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\UPG2LoPXwc7OWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\ZunTSaNJLBVfWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\o0qT3dWYBP7ZHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\oOPEmFmu_xsJCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 5, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 5
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\pSE1jchbiT9aHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidioXPwUyynlHg5\suOrwW4ZcUbjWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\02zdBXl47cvzHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\02zdBXl47cvzcookies.sqlite
SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\2jQJv37iJ0lzCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\3b6N2Xdh3CYwWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\3b6N2Xdh3CYwplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\8ghN89CsjOW1Login Data For Account
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\D87fZN3R3jFeWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\D87fZN3R3jFeplaces.sqlite
SQLite 3.x database, user version 75, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 2, database pages 46, cookie 0x26, schema 4, UTF-8, version-valid-for 2
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\Ei8DrAmaYu9KLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\IWPfiAXUTJTSHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 39, cookie 0x20, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\KvHrxJ77cmUgLogin Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 25, cookie 0xe, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\QdX9ITDLyCRBWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\UPG2LoPXwc7OWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\ZunTSaNJLBVfWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\o0qT3dWYBP7ZHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\oOPEmFmu_xsJCookies
SQLite 3.x database, last written using SQLite version 3042000, file counter 5, database pages 5, cookie 0x3, schema 4, UTF-8, version-valid-for 5
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\pSE1jchbiT9aHistory
SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 1
dropped
C:\Users\user\AppData\Local\Temp\heidipbqnrM0s9U5u\suOrwW4ZcUbjWeb Data
SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 7, database pages 89, cookie 0x36, schema 4, UTF-8, version-valid-for 7
dropped
There are 2093 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
"C:\Users\user\Desktop\831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe"
malicious
C:\Users\Public\Libraries\(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
"C:\Users\Public\Libraries\(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe"
malicious
C:\Users\Public\Libraries\(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
"C:\Users\Public\Libraries\(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe"
malicious
C:\Windows\SysWOW64\calc.exe
C:\Windows\System32\calc.exe
malicious
C:\Windows\SysWOW64\calc.exe
C:\Windows\System32\calc.exe
malicious
C:\Windows\SysWOW64\calc.exe
C:\Windows\System32\calc.exe
malicious
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 7820 -s 1920
C:\Windows\SysWOW64\WerFault.exe
C:\Windows\SysWOW64\WerFault.exe -u -p 7668 -s 1996

URLs

Name
IP
Malicious
https://duckduckgo.com/chrome_newtab
unknown
https://duckduckgo.com/ac/?q=
unknown
https://sectigo.com/CPS0
unknown
https://www.google.com/images/branding/product/ico/googleg_lodp.ico
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
unknown
http://ocsp.sectigo.com0
unknown
https://db-ip.com/
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
unknown
https://ipinfo.io/https://www.maxmind.com/en/locate-my-ip-addressWs2_32.dll
unknown
https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
unknown
https://db-ip.com:443/demo/home.php?s=191.96.150.225P
unknown
https://t.me/RiseProSUPPORT
unknown
https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
unknown
https://t.me/risepro_botBmM
unknown
http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
unknown
https://trusttoken.dev
unknown
https://ipinfo.io:443/widget/demo/191.96.150.225
unknown
https://www.ecosia.org/newtab/
unknown
https://db-ip.com/demo/home.php?s=191.96.150.225
104.26.5.15
https://ipinfo.io/Mozilla/5.0
unknown
https://t.me/risepro_bot:d1
unknown
https://support.mozilla.org/kb/customize-firefox-controls-buttons-and-toolbars?utm_source=firefox-br
unknown
https://t.me/risepro_botkM
unknown
https://ac.ecosia.org/autocomplete?q=
unknown
https://t.me/risepro_bot
unknown
http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
unknown
https://ipinfo.io/
unknown
https://www.maxmind.com/en/locate-my-ip-address
unknown
https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
unknown
http://www.winimage.com/zLibDll
unknown
https://ipinfo.io/widget/demo/191.96.150.225
34.117.186.192
https://t.me/RiseProSUPPORT?
unknown
https://t.me/RiseProSUPPORTApplication
unknown
https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
unknown
https://support.mozilla.org/products/firefoxgro.allizom.troppus.S3DiLP_FhcLK
unknown
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bastermedia.com
94.156.8.188
malicious
ipinfo.io
34.117.186.192
db-ip.com
104.26.5.15

IPs

IP
Domain
Country
Malicious
94.156.8.188
bastermedia.com
Bulgaria
malicious
34.117.186.192
ipinfo.io
United States
104.26.5.15
db-ip.com
United States

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(e159e87fbe0192614bd548893ae5f53d)831107010C8578AD95A12C5498B03755EAC398B5BBC0D.exe
malicious

Memdumps

Base Address
Regiontype
Protect
Malicious
44A0000
direct allocation
page read and write
malicious
2800000
remote allocation
page execute read
malicious
3402000
direct allocation
page read and write
malicious
4491000
direct allocation
page execute and read and write
malicious
4AAA000
heap
page read and write
malicious
4AA9000
heap
page read and write
malicious
4AA7000
heap
page read and write
malicious
59C0000
heap
page read and write
malicious
6079000
heap
page read and write
malicious
59A9000
heap
page read and write
malicious
2600000
remote allocation
page execute read
malicious
32B5000
heap
page read and write
malicious
5451000
heap
page read and write
malicious
5978000
heap
page read and write
malicious
4BC7000
heap
page read and write
malicious
45F1000
direct allocation
page execute and read and write
malicious
4D31000
direct allocation
page execute and read and write
malicious
4190000
direct allocation
page read and write
malicious
2E00000
remote allocation
page execute read
malicious
5955000
heap
page read and write
malicious
59C0000
heap
page read and write
malicious
4B00000
direct allocation
page read and write
malicious
2CF0000
direct allocation
page read and write
415E000
direct allocation
page read and write
6ADA000
direct allocation
page read and write
4AA7000
heap
page read and write
10EE000
unkown
page execute read
55B4000
heap
page read and write
439E000
direct allocation
page read and write
36F2000
direct allocation
page read and write
4ACD000
heap
page read and write
5A62000
heap
page read and write
2A97000
heap
page read and write
2D68000
direct allocation
page read and write
510A000
heap
page read and write
52DB000
heap
page read and write
4ACC000
heap
page read and write
3A74000
direct allocation
page read and write
59D8000
heap
page read and write
7BB4000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
509B000
heap
page read and write
7192000
direct allocation
page read and write
58EC000
heap
page read and write
289C000
heap
page read and write
4D11000
heap
page read and write
39B4000
direct allocation
page read and write
32FC000
heap
page read and write
2DBC000
direct allocation
page read and write
5CEF000
direct allocation
page read and write
6734000
direct allocation
page read and write
6DB4000
direct allocation
page read and write
796C000
direct allocation
page read and write
537C000
heap
page read and write
7022000
direct allocation
page read and write
4D18000
heap
page read and write
7AF4000
direct allocation
page read and write
75C2000
direct allocation
page read and write
7C98000
direct allocation
page read and write
50FA000
heap
page read and write
4D4A000
heap
page read and write
2F40000
direct allocation
page read and write
73C0000
direct allocation
page read and write
486E000
direct allocation
page read and write
4AA7000
heap
page read and write
7813000
direct allocation
page read and write
6916000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
4A7B000
heap
page read and write
4AB6000
heap
page read and write
78B1000
direct allocation
page read and write
7568000
direct allocation
page read and write
32FC000
heap
page read and write
6A74000
direct allocation
page read and write
2A75000
heap
page read and write
C89000
direct allocation
page read and write
5304000
heap
page read and write
2C37000
direct allocation
page read and write
759E000
direct allocation
page read and write
7250000
direct allocation
page read and write
532D000
heap
page read and write
4D10000
heap
page read and write
2880000
heap
page read and write
6FAE000
direct allocation
page read and write
54B7000
heap
page read and write
765C000
direct allocation
page read and write
39FE000
direct allocation
page read and write
4D53000
heap
page read and write
4D78000
heap
page read and write
223D000
stack
page read and write
6C90000
direct allocation
page read and write
316E000
direct allocation
page read and write
76A8000
direct allocation
page read and write
769A000
direct allocation
page read and write
432E000
direct allocation
page read and write
31C0000
direct allocation
page read and write
7838000
direct allocation
page read and write
22FFF000
stack
page read and write
A4C000
heap
page read and write
5305000
heap
page read and write
4D54000
heap
page read and write
3246000
heap
page read and write
2874000
heap
page read and write
3D24000
direct allocation
page read and write
4D15000
heap
page read and write
510E000
heap
page read and write
4AC6000
heap
page read and write
5337000
heap
page read and write
5327000
heap
page read and write
4AC6000
heap
page read and write
510E000
heap
page read and write
3746000
direct allocation
page read and write
510E000
heap
page read and write
6CB4000
direct allocation
page read and write
488F000
direct allocation
page read and write
2FC5000
direct allocation
page read and write
4846000
direct allocation
page read and write
47B2000
direct allocation
page read and write
2C58000
direct allocation
page read and write
5036000
heap
page read and write
307E000
direct allocation
page read and write
58C9000
heap
page read and write
5A94000
heap
page read and write
6F9E000
direct allocation
page read and write
50CB000
heap
page read and write
7C4E000
direct allocation
page read and write
28A1000
direct allocation
page read and write
32DD000
heap
page read and write
6A92000
direct allocation
page read and write
4D74000
heap
page read and write
532C000
heap
page read and write
6F8A000
direct allocation
page read and write
6CA2000
direct allocation
page read and write
2B3A000
direct allocation
page read and write
2E50000
direct allocation
page read and write
3070000
direct allocation
page read and write
58E8000
heap
page read and write
5315000
heap
page read and write
58F4000
heap
page read and write
4AB0000
heap
page read and write
4F60000
trusted library allocation
page read and write
1A13000
unkown
page readonly
594E000
heap
page read and write
7D78000
direct allocation
page read and write
543A000
heap
page read and write
2D6A000
direct allocation
page read and write
7C10000
direct allocation
page read and write
532C000
heap
page read and write
4AAE000
heap
page read and write
386C000
direct allocation
page read and write
7990000
direct allocation
page read and write
43AC000
direct allocation
page read and write
58E8000
heap
page read and write
28AE000
heap
page read and write
4AB1000
heap
page read and write
3242000
heap
page read and write
52DB000
heap
page read and write
5313000
heap
page read and write
4D20000
heap
page read and write
4FE0000
heap
page read and write
4F60000
trusted library allocation
page read and write
510E000
heap
page read and write
510A000
heap
page read and write
28A5000
heap
page read and write
7D4A000
direct allocation
page read and write
4D27000
heap
page read and write
7D90000
direct allocation
page read and write
286D000
stack
page read and write
4D53000
heap
page read and write
2F8E000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
3984000
direct allocation
page read and write
52C6000
heap
page read and write
6EBA000
direct allocation
page read and write
3CC6000
direct allocation
page read and write
3A36000
direct allocation
page read and write
55B4000
heap
page read and write
4D4A000
heap
page read and write
4AC6000
heap
page read and write
4CE4000
heap
page read and write
4CE0000
trusted library allocation
page read and write
52B9000
heap
page read and write
40FA000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
4D2F000
heap
page read and write
2F18000
direct allocation
page read and write
47FC000
direct allocation
page read and write
758C000
direct allocation
page read and write
4419000
direct allocation
page read and write
3EF0000
direct allocation
page read and write
7E64000
direct allocation
page read and write
10E8000
unkown
page execute read
595D000
heap
page read and write
6D46000
direct allocation
page read and write
4DCC000
heap
page read and write
58B7000
heap
page read and write
288A000
heap
page read and write
6D0E000
direct allocation
page read and write
2EC4000
direct allocation
page read and write
2802000
heap
page read and write
5868000
heap
page read and write
4D1F000
heap
page read and write
535D000
heap
page read and write
2AC7000
direct allocation
page read and write
2880000
heap
page read and write
7A32000
direct allocation
page read and write
42A4000
direct allocation
page read and write
2B1A000
direct allocation
page read and write
4452000
direct allocation
page read and write
3C76000
direct allocation
page read and write
441C000
direct allocation
page read and write
74FD000
direct allocation
page read and write
5870000
heap
page read and write
32FC000
heap
page read and write
5C3D000
direct allocation
page read and write
3182000
direct allocation
page read and write
247A6000
direct allocation
page read and write
577F000
direct allocation
page read and write
4D4A000
heap
page read and write
2C99000
direct allocation
page read and write
7C3E000
direct allocation
page read and write
442E000
direct allocation
page read and write
3A3E000
direct allocation
page read and write
2CD6000
direct allocation
page read and write
52DA000
heap
page read and write
7140000
direct allocation
page read and write
7824000
direct allocation
page read and write
747A000
direct allocation
page read and write
1689000
unkown
page write copy
75A6000
direct allocation
page read and write
33C8000
direct allocation
page read and write
2880000
heap
page read and write
4D8C000
heap
page read and write
6AA6000
direct allocation
page read and write
43A3000
direct allocation
page read and write
1DE0000
heap
page read and write
67C4000
direct allocation
page read and write
38DC000
direct allocation
page read and write
7361000
direct allocation
page read and write
3C56000
direct allocation
page read and write
4D0D000
heap
page read and write
118E000
unkown
page execute read
7F21000
direct allocation
page read and write
532D000
heap
page read and write
7F08000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
3928000
direct allocation
page read and write
C8D000
stack
page read and write
5116000
heap
page read and write
54C9000
heap
page read and write
4AA7000
heap
page read and write
4743000
direct allocation
page read and write
555C000
heap
page read and write
6732000
heap
page read and write
7A22000
direct allocation
page read and write
2DC2000
direct allocation
page read and write
5327000
heap
page read and write
6DCA000
direct allocation
page read and write
253E0000
direct allocation
page read and write
28A2000
heap
page read and write
3E94000
direct allocation
page read and write
3008000
direct allocation
page read and write
43DB000
direct allocation
page read and write
58B9000
heap
page read and write
3684000
direct allocation
page read and write
3B16000
direct allocation
page read and write
52CF000
heap
page read and write
7EC6000
direct allocation
page read and write
7E1C000
direct allocation
page read and write
288B000
heap
page read and write
2F7F000
direct allocation
page read and write
52DC000
heap
page read and write
71FC000
direct allocation
page read and write
58E8000
heap
page read and write
7191000
direct allocation
page read and write
4ABB000
heap
page read and write
58ED000
heap
page read and write
3C42000
direct allocation
page read and write
2C4B000
direct allocation
page read and write
6ACC000
direct allocation
page read and write
4AAA000
heap
page read and write
696C000
direct allocation
page read and write
4CF9000
heap
page read and write
3814000
direct allocation
page read and write
7C90000
direct allocation
page read and write
5C17000
heap
page read and write
6D58000
direct allocation
page read and write
288A000
heap
page read and write
7B02000
direct allocation
page read and write
3030000
direct allocation
page read and write
58C8000
heap
page read and write
5414000
heap
page read and write
4CE7000
heap
page read and write
289B000
heap
page read and write
2DFB000
direct allocation
page read and write
32D2000
heap
page read and write
46E4000
direct allocation
page read and write
79E6000
direct allocation
page read and write
583F000
heap
page read and write
252C8000
direct allocation
page read and write
7344000
direct allocation
page read and write
3718000
direct allocation
page read and write
7DF4000
direct allocation
page read and write
C82000
direct allocation
page read and write
6B36000
direct allocation
page read and write
28B5000
heap
page read and write
5344000
heap
page read and write
38CE000
direct allocation
page read and write
4154000
direct allocation
page read and write
5760000
heap
page read and write
4AE0000
heap
page read and write
36B2000
direct allocation
page read and write
4D4A000
heap
page read and write
7388000
direct allocation
page read and write
28AA000
direct allocation
page read and write
7376000
direct allocation
page read and write
58E8000
heap
page read and write
6E26000
direct allocation
page read and write
4D2D000
heap
page read and write
4D1C000
heap
page read and write
58E8000
heap
page read and write
4D27000
heap
page read and write
68CA000
direct allocation
page read and write
32F2000
heap
page read and write
5CC7000
direct allocation
page read and write
4D27000
heap
page read and write
2893000
heap
page read and write
5304000
heap
page read and write
4ACB000
heap
page read and write
527E000
stack
page read and write
4A60000
heap
page read and write
52C6000
heap
page read and write
2E74000
direct allocation
page read and write
24CB4000
direct allocation
page read and write
6EEE000
direct allocation
page read and write
2EED000
direct allocation
page read and write
3906000
direct allocation
page read and write
5415000
heap
page read and write
252DD000
direct allocation
page read and write
47CB000
direct allocation
page read and write
4AB0000
heap
page read and write
4B38000
heap
page read and write
6924000
direct allocation
page read and write
7E2A000
direct allocation
page read and write
2A75000
heap
page read and write
32E0000
heap
page read and write
6746000
direct allocation
page read and write
58DE000
heap
page read and write
743C000
direct allocation
page read and write
4D3F000
heap
page read and write
4AAE000
heap
page read and write
36EA000
direct allocation
page read and write
288A000
heap
page read and write
50EA000
heap
page read and write
28B6000
heap
page read and write
6E34000
direct allocation
page read and write
4D1D000
heap
page read and write
58C7000
heap
page read and write
28B5000
heap
page read and write
5349000
heap
page read and write
7882000
direct allocation
page read and write
2A3F000
stack
page read and write
58B9000
heap
page read and write
7166000
direct allocation
page read and write
74E2000
direct allocation
page read and write
4B3E000
heap
page read and write
58EC000
heap
page read and write
564E000
stack
page read and write
4B12000
heap
page read and write
5321000
heap
page read and write
3990000
direct allocation
page read and write
7514000
direct allocation
page read and write
36C6000
direct allocation
page read and write
41FC000
direct allocation
page read and write
4D0F000
heap
page read and write
2A9E000
heap
page read and write
37C9000
direct allocation
page read and write
46E6000
direct allocation
page read and write
287B000
heap
page read and write
28A6000
heap
page read and write
421A000
direct allocation
page read and write
32C1000
heap
page read and write
2942000
direct allocation
page read and write
7826000
direct allocation
page read and write
2880000
heap
page read and write
58ED000
heap
page read and write
551C000
heap
page read and write
5304000
heap
page read and write
3CFA000
direct allocation
page read and write
7B86000
direct allocation
page read and write
2CC4000
direct allocation
page read and write
4D3F000
heap
page read and write
532D000
heap
page read and write
56EA000
heap
page read and write
58E8000
heap
page read and write
4D3F000
heap
page read and write
128C000
unkown
page read and write
32D2000
heap
page read and write
4AE4000
heap
page read and write
7DF0000
direct allocation
page read and write
4AE5000
heap
page read and write
4D53000
heap
page read and write
58E8000
heap
page read and write
5116000
heap
page read and write
6B98000
direct allocation
page read and write
28EE000
direct allocation
page read and write
5325000
heap
page read and write
58E8000
heap
page read and write
73AC000
direct allocation
page read and write
50FF000
heap
page read and write
32D3000
heap
page read and write
6D7A000
direct allocation
page read and write
532F000
heap
page read and write
3890000
direct allocation
page read and write
3A4A000
direct allocation
page read and write
4130000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
50EA000
heap
page read and write
4D4A000
heap
page read and write
529C000
heap
page read and write
50EA000
heap
page read and write
38A4000
direct allocation
page read and write
7262000
direct allocation
page read and write
2DD8000
direct allocation
page read and write
6B8E000
direct allocation
page read and write
30DE000
direct allocation
page read and write
242E000
stack
page read and write
5954000
heap
page read and write
4AB1000
heap
page read and write
6EDE000
direct allocation
page read and write
42DD000
direct allocation
page read and write
4D3F000
heap
page read and write
6BCB000
direct allocation
page read and write
2DC4000
direct allocation
page read and write
58F4000
heap
page read and write
394C000
direct allocation
page read and write
4274000
direct allocation
page read and write
7174000
direct allocation
page read and write
2A70000
heap
page read and write
510A000
heap
page read and write
50FF000
heap
page read and write
58D8000
heap
page read and write
4D53000
heap
page read and write
2D36000
direct allocation
page read and write
2FA8000
direct allocation
page read and write
533F000
heap
page read and write
7236000
direct allocation
page read and write
58C8000
heap
page read and write
32EA000
heap
page read and write
4D53000
heap
page read and write
32E0000
heap
page read and write
4D54000
heap
page read and write
58B9000
heap
page read and write
2D46000
direct allocation
page read and write
6AB6000
direct allocation
page read and write
4D83000
heap
page read and write
383A000
direct allocation
page read and write
510A000
heap
page read and write
58C9000
heap
page read and write
6BDC000
direct allocation
page read and write
5678000
heap
page read and write
2A04000
heap
page read and write
2A04000
heap
page read and write
6C6A000
direct allocation
page read and write
28AF000
heap
page read and write
58F4000
heap
page read and write
58C9000
heap
page read and write
3BF8000
direct allocation
page read and write
510A000
heap
page read and write
544D000
heap
page read and write
50DB000
heap
page read and write
77BC000
direct allocation
page read and write
4AC6000
heap
page read and write
3D32000
direct allocation
page read and write
4D2B000
heap
page read and write
3CEC000
direct allocation
page read and write
5304000
heap
page read and write
5678000
heap
page read and write
561D000
heap
page read and write
3DB6000
direct allocation
page read and write
447E000
direct allocation
page read and write
4B3E000
heap
page read and write
42ED000
direct allocation
page read and write
47E8000
direct allocation
page read and write
471E000
direct allocation
page read and write
4D27000
heap
page read and write
5BC7000
direct allocation
page read and write
530E000
heap
page read and write
58E8000
heap
page read and write
58A4000
heap
page read and write
5550000
trusted library allocation
page read and write
7792000
direct allocation
page read and write
2ED8000
direct allocation
page read and write
6B56000
direct allocation
page read and write
439E000
direct allocation
page read and write
4245000
direct allocation
page read and write
5AB4000
heap
page read and write
2874000
heap
page read and write
47EC000
direct allocation
page read and write
1C3E000
unkown
page read and write
2874000
heap
page read and write
4768000
direct allocation
page read and write
55B4000
heap
page read and write
4AC6000
heap
page read and write
2C3F000
direct allocation
page read and write
7CA8000
direct allocation
page read and write
167C000
unkown
page write copy
6B76000
direct allocation
page read and write
474C000
direct allocation
page read and write
4D3F000
heap
page read and write
4040000
direct allocation
page read and write
6BBE000
direct allocation
page read and write
4B5D000
heap
page read and write
6DB4000
direct allocation
page read and write
36FC000
direct allocation
page read and write
2944000
direct allocation
page read and write
31AA000
direct allocation
page read and write
38F2000
direct allocation
page read and write
4D4A000
heap
page read and write
2893000
heap
page read and write
4A7C000
heap
page read and write
4A5E000
stack
page read and write
29B6000
direct allocation
page read and write
4D53000
heap
page read and write
535A000
heap
page read and write
4260000
direct allocation
page read and write
4D4A000
heap
page read and write
5116000
heap
page read and write
2874000
heap
page read and write
27E3000
heap
page read and write
358F000
direct allocation
page read and write
4AAE000
heap
page read and write
32FC000
heap
page read and write
4D3F000
heap
page read and write
5198000
heap
page read and write
2D92000
direct allocation
page read and write
7914000
direct allocation
page read and write
5761000
heap
page read and write
4212000
direct allocation
page read and write
4ACC000
heap
page read and write
76BC000
direct allocation
page read and write
2600000
direct allocation
page read and write
58E8000
heap
page read and write
420C000
direct allocation
page read and write
2C4B000
direct allocation
page read and write
31B8000
direct allocation
page read and write
67B8000
direct allocation
page read and write
5325000
heap
page read and write
7954000
direct allocation
page read and write
785E000
direct allocation
page read and write
52D3000
heap
page read and write
4D3F000
heap
page read and write
5305000
heap
page read and write
6F56000
direct allocation
page read and write
2EFC000
direct allocation
page read and write
6C14000
direct allocation
page read and write
510E000
heap
page read and write
4D1C000
heap
page read and write
680C000
direct allocation
page read and write
2874000
heap
page read and write
5315000
heap
page read and write
4AC6000
heap
page read and write
539D000
heap
page read and write
2CD8000
direct allocation
page read and write
4795000
direct allocation
page read and write
47E7000
direct allocation
page read and write
721A000
direct allocation
page read and write
4AA7000
heap
page read and write
58C8000
heap
page read and write
4CE8000
heap
page read and write
9F0000
direct allocation
page read and write
2880000
heap
page read and write
28A1000
heap
page read and write
66E2000
direct allocation
page read and write
58E8000
heap
page read and write
35D8000
direct allocation
page read and write
3178000
direct allocation
page read and write
5116000
heap
page read and write
30B0000
heap
page read and write
58F4000
heap
page read and write
5304000
heap
page read and write
7712000
direct allocation
page read and write
5CA0000
direct allocation
page read and write
3610000
direct allocation
page read and write
2DEE000
direct allocation
page read and write
4AE7000
heap
page read and write
6A10000
direct allocation
page read and write
290C000
direct allocation
page read and write
58EC000
heap
page read and write
2E98000
direct allocation
page read and write
31E4000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
6A0A000
direct allocation
page read and write
4ADF000
heap
page read and write
4D63000
heap
page read and write
3C64000
direct allocation
page read and write
78DA000
direct allocation
page read and write
378C000
direct allocation
page read and write
71C8000
direct allocation
page read and write
5430000
heap
page read and write
4AD0000
heap
page read and write
4282000
direct allocation
page read and write
516B000
heap
page read and write
517E000
heap
page read and write
27A0000
direct allocation
page read and write
6D72000
direct allocation
page read and write
4CE3000
heap
page read and write
4CF0000
remote allocation
page read and write
5567000
heap
page read and write
4AAE000
heap
page read and write
B77000
direct allocation
page read and write
510A000
heap
page read and write
2BD6000
direct allocation
page read and write
4D4A000
heap
page read and write
67D4000
direct allocation
page read and write
510A000
heap
page read and write
2EA4000
direct allocation
page read and write
6C4A000
direct allocation
page read and write
28AE000
heap
page read and write
2A70000
heap
page read and write
595C000
heap
page read and write
4A9D000
heap
page read and write
3E61000
direct allocation
page read and write
4D2D000
heap
page read and write
58D8000
heap
page read and write
58C9000
heap
page read and write
419E000
direct allocation
page read and write
2870000
direct allocation
page read and write
792E000
direct allocation
page read and write
5CB5000
direct allocation
page read and write
2260000
heap
page read and write
58C9000
heap
page read and write
58F4000
heap
page read and write
36BE000
direct allocation
page read and write
3BD0000
direct allocation
page read and write
2895000
heap
page read and write
2C67000
direct allocation
page read and write
58E8000
heap
page read and write
3DC8000
direct allocation
page read and write
2871000
heap
page read and write
27A9000
direct allocation
page read and write
2A70000
heap
page read and write
504B000
heap
page read and write
3214000
direct allocation
page read and write
237FF000
stack
page read and write
4770000
heap
page read and write
58EC000
heap
page read and write
6D8E000
direct allocation
page read and write
4D72000
heap
page read and write
2D34000
direct allocation
page read and write
4D30000
heap
page read and write
798A000
direct allocation
page read and write
2A98000
heap
page read and write
355E000
direct allocation
page read and write
6D20000
direct allocation
page read and write
5116000
heap
page read and write
3348000
direct allocation
page read and write
4CD4000
heap
page read and write
7556000
direct allocation
page read and write
6EF8000
direct allocation
page read and write
2A70000
heap
page read and write
7BB6000
direct allocation
page read and write
2E86000
direct allocation
page read and write
1808000
unkown
page write copy
3A86000
direct allocation
page read and write
495A000
direct allocation
page read and write
39AA000
direct allocation
page read and write
2B78000
direct allocation
page read and write
32F2000
heap
page read and write
58F4000
heap
page read and write
7A64000
direct allocation
page read and write
58B9000
heap
page read and write
28BA000
heap
page read and write
58D8000
heap
page read and write
4A7C000
heap
page read and write
42DA000
direct allocation
page read and write
2FA0000
heap
page read and write
56A0000
heap
page read and write
27E3000
heap
page read and write
6F0E000
direct allocation
page read and write
3134000
direct allocation
page read and write
239D000
stack
page read and write
6996000
direct allocation
page read and write
28B6000
direct allocation
page read and write
2915000
heap
page read and write
3702000
direct allocation
page read and write
2DB9000
direct allocation
page read and write
6F70000
direct allocation
page read and write
28AD000
stack
page read and write
58F4000
heap
page read and write
517B000
heap
page read and write
4732000
direct allocation
page read and write
4A77000
heap
page read and write
42E3000
direct allocation
page read and write
77DE000
direct allocation
page read and write
6B06000
direct allocation
page read and write
7D9C000
direct allocation
page read and write
7636000
direct allocation
page read and write
5305000
heap
page read and write
7C66000
direct allocation
page read and write
58E8000
heap
page read and write
4D4A000
heap
page read and write
5562000
heap
page read and write
287B000
heap
page read and write
4832000
direct allocation
page read and write
50A6000
heap
page read and write
2A70000
heap
page read and write
594C000
heap
page read and write
7E0A000
direct allocation
page read and write
7B78000
direct allocation
page read and write
28B6000
heap
page read and write
5998000
heap
page read and write
78B8000
direct allocation
page read and write
4726000
direct allocation
page read and write
754A000
direct allocation
page read and write
4ACD000
heap
page read and write
4ADC000
heap
page read and write
92C000
stack
page read and write
2B46000
direct allocation
page read and write
6CC8000
direct allocation
page read and write
56C1000
heap
page read and write
5539000
heap
page read and write
58EC000
heap
page read and write
45EA000
direct allocation
page read and write
4ACA000
heap
page read and write
2FD1000
direct allocation
page read and write
2C80000
direct allocation
page read and write
374A000
direct allocation
page read and write
4D26000
heap
page read and write
487C000
direct allocation
page read and write
5CD7000
direct allocation
page read and write
32DE000
heap
page read and write
28B6000
heap
page read and write
532D000
heap
page read and write
57FF000
heap
page read and write
58D8000
heap
page read and write
BCE000
stack
page read and write
58D8000
heap
page read and write
420A000
direct allocation
page read and write
31AE000
direct allocation
page read and write
3BC2000
direct allocation
page read and write
6D36000
direct allocation
page read and write
72A0000
direct allocation
page read and write
288A000
heap
page read and write
2DE0000
direct allocation
page read and write
2D1E000
direct allocation
page read and write
4315000
direct allocation
page read and write
7CF2000
direct allocation
page read and write
57F2000
heap
page read and write
4636000
direct allocation
page read and write
2E6E000
direct allocation
page read and write
2DF4000
direct allocation
page read and write
4D27000
heap
page read and write
5344000
heap
page read and write
28A4000
heap
page read and write
58EC000
heap
page read and write
5C17000
direct allocation
page read and write
2DF6000
direct allocation
page read and write
6C46000
direct allocation
page read and write
3806000
direct allocation
page read and write
6DEE000
direct allocation
page read and write
4D27000
heap
page read and write
7622000
direct allocation
page read and write
D35000
unkown
page execute read
3DD2000
direct allocation
page read and write
285C000
direct allocation
page read and write
2BB4000
direct allocation
page read and write
5116000
heap
page read and write
6B98000
direct allocation
page read and write
7410000
direct allocation
page read and write
3001000
direct allocation
page read and write
2934000
direct allocation
page read and write
3B1A000
direct allocation
page read and write
58F4000
heap
page read and write
28A2000
heap
page read and write
19AB000
unkown
page readonly
2D92000
direct allocation
page read and write
5315000
heap
page read and write
4C8E000
stack
page read and write
7F1A000
direct allocation
page read and write
58E8000
heap
page read and write
6E84000
direct allocation
page read and write
4D27000
heap
page read and write
7330000
direct allocation
page read and write
510E000
heap
page read and write
4AD0000
heap
page read and write
288A000
heap
page read and write
288A000
heap
page read and write
7748000
direct allocation
page read and write
29F1000
heap
page read and write
7D66000
direct allocation
page read and write
7B36000
direct allocation
page read and write
6D68000
direct allocation
page read and write
6ABA000
direct allocation
page read and write
76D2000
direct allocation
page read and write
28BE000
heap
page read and write
5728000
heap
page read and write
4302000
direct allocation
page read and write
2812000
direct allocation
page read and write
5491000
heap
page read and write
7D34000
direct allocation
page read and write
2906000
direct allocation
page read and write
4AA9000
heap
page read and write
32DE000
heap
page read and write
32E5000
heap
page read and write
72B2000
direct allocation
page read and write
422A000
direct allocation
page read and write
2C54000
direct allocation
page read and write
25EC000
stack
page read and write
7E08000
direct allocation
page read and write
4AAE000
heap
page read and write
7486000
direct allocation
page read and write
2DCE000
direct allocation
page read and write
4ED0000
trusted library allocation
page read and write
7AD6000
direct allocation
page read and write
6C9C000
direct allocation
page read and write
706C000
direct allocation
page read and write
32FC000
heap
page read and write
4D17000
heap
page read and write
58F4000
heap
page read and write
2A61000
heap
page read and write
7894000
direct allocation
page read and write
3F9A000
direct allocation
page read and write
4D3F000
heap
page read and write
73F6000
direct allocation
page read and write
413A000
direct allocation
page read and write
4D63000
heap
page read and write
6936000
direct allocation
page read and write
6A66000
direct allocation
page read and write
32C1000
heap
page read and write
50A4000
heap
page read and write
78C4000
direct allocation
page read and write
5271000
heap
page read and write
3F18000
direct allocation
page read and write
4F00000
heap
page read and write
2A64000
heap
page read and write
B7B000
direct allocation
page read and write
32F2000
heap
page read and write
7108000
direct allocation
page read and write
4D2A000
heap
page read and write
2D9E000
direct allocation
page read and write
7338000
direct allocation
page read and write
2EA4000
direct allocation
page read and write
4D53000
heap
page read and write
5304000
heap
page read and write
2D50000
direct allocation
page read and write
58B9000
heap
page read and write
2BCC000
direct allocation
page read and write
7C44000
direct allocation
page read and write
4D27000
heap
page read and write
1C81000
unkown
page read and write
5064000
heap
page read and write
5324000
heap
page read and write
76E2000
direct allocation
page read and write
5586000
heap
page read and write
6D82000
direct allocation
page read and write
58EC000
heap
page read and write
5551000
heap
page read and write
28BE000
heap
page read and write
5CBE000
direct allocation
page read and write
4D4A000
heap
page read and write
6D48000
direct allocation
page read and write
2892000
heap
page read and write
32C3000
heap
page read and write
7248000
direct allocation
page read and write
58D8000
heap
page read and write
4D27000
heap
page read and write
771B000
direct allocation
page read and write
50BB000
heap
page read and write
5BD8000
direct allocation
page read and write
58DE000
heap
page read and write
30FF000
direct allocation
page read and write
58F4000
heap
page read and write
2892000
heap
page read and write
5054000
heap
page read and write
32F2000
heap
page read and write
32C6000
direct allocation
page read and write
28BE000
heap
page read and write
7240000
direct allocation
page read and write
233FF000
stack
page read and write
58EC000
heap
page read and write
2A70000
heap
page read and write
4A7C000
heap
page read and write
5352000
heap
page read and write
6F0E000
direct allocation
page read and write
2D58000
direct allocation
page read and write
251F6000
direct allocation
page read and write
43E4000
direct allocation
page read and write
3B9C000
direct allocation
page read and write
31D2000
direct allocation
page read and write
5315000
heap
page read and write
4AE2000
heap
page read and write
5305000
heap
page read and write
3236000
direct allocation
page read and write
47FC000
stack
page read and write
79EE000
direct allocation
page read and write
32DA000
heap
page read and write
3B3C000
direct allocation
page read and write
2C3C000
direct allocation
page read and write
2941000
direct allocation
page read and write
52D7000
heap
page read and write
52FD000
heap
page read and write
7926000
direct allocation
page read and write
2481D000
stack
page read and write
2B50000
direct allocation
page read and write
58F4000
heap
page read and write
5300000
heap
page read and write
799B000
direct allocation
page read and write
2802000
direct allocation
page read and write
32F2000
heap
page read and write
4AC7000
heap
page read and write
58C9000
heap
page read and write
43D2000
direct allocation
page read and write
2892000
heap
page read and write
30CC000
direct allocation
page read and write
288A000
heap
page read and write
2EE0000
direct allocation
page read and write
B70000
direct allocation
page read and write
50DB000
heap
page read and write
2893000
heap
page read and write
532D000
heap
page read and write
2C78000
direct allocation
page read and write
5116000
heap
page read and write
75FE000
direct allocation
page read and write
7CEA000
direct allocation
page read and write
58B9000
heap
page read and write
54D7000
heap
page read and write
5318000
heap
page read and write
50EA000
heap
page read and write
2BBD000
stack
page read and write
6AEE000
direct allocation
page read and write
72A0000
direct allocation
page read and write
10F4000
unkown
page execute read
50FA000
heap
page read and write
4402000
direct allocation
page read and write
42CC000
direct allocation
page read and write
728E000
direct allocation
page read and write
298A000
stack
page read and write
2A61000
heap
page read and write
4D16000
heap
page read and write
58EC000
heap
page read and write
28AE000
heap
page read and write
27C0000
heap
page read and write
510A000
heap
page read and write
3B52000
direct allocation
page read and write
510A000
heap
page read and write
7D88000
direct allocation
page read and write
2DA2000
direct allocation
page read and write
77E2000
direct allocation
page read and write
590D000
heap
page read and write
466E000
direct allocation
page read and write
165E000
unkown
page readonly
368E000
direct allocation
page read and write
7366000
direct allocation
page read and write
5871000
heap
page read and write
385E000
direct allocation
page read and write
2E49000
direct allocation
page read and write
7D42000
direct allocation
page read and write
732E000
direct allocation
page read and write
4AAA000
heap
page read and write
497A000
direct allocation
page read and write
7A80000
direct allocation
page read and write
6866000
direct allocation
page read and write
4A9B000
heap
page read and write
58C9000
heap
page read and write
5365000
heap
page read and write
52D7000
heap
page read and write
2BA8000
direct allocation
page read and write
7BF4000
direct allocation
page read and write
2E94000
direct allocation
page read and write
3C8A000
direct allocation
page read and write
6912000
direct allocation
page read and write
7B94000
direct allocation
page read and write
2A98000
heap
page read and write
75DA000
direct allocation
page read and write
10F0000
unkown
page execute read
553B000
heap
page read and write
1C86000
unkown
page read and write
5660000
heap
page read and write
289A000
heap
page read and write
3A5E000
direct allocation
page read and write
44C2000
direct allocation
page read and write
74A4000
direct allocation
page read and write
74BE000
direct allocation
page read and write
231D000
stack
page read and write
744E000
direct allocation
page read and write
4AA9000
heap
page read and write
363A000
direct allocation
page read and write
58E8000
heap
page read and write
4D3F000
heap
page read and write
4D7E000
heap
page read and write
4D4A000
heap
page read and write
2DC6000
direct allocation
page read and write
2D70000
direct allocation
page read and write
2814000
direct allocation
page read and write
4D10000
heap
page read and write
2A81000
heap
page read and write
5315000
heap
page read and write
52D7000
heap
page read and write
4D3F000
heap
page read and write
3239000
heap
page read and write
5305000
heap
page read and write
50DA000
heap
page read and write
4A6B000
heap
page read and write
470C000
direct allocation
page read and write
532F000
heap
page read and write
253C000
heap
page read and write
29B0000
heap
page read and write
4D14000
heap
page read and write
4D64000
heap
page read and write
451B000
direct allocation
page read and write
4A81000
heap
page read and write
5C35000
direct allocation
page read and write
46B8000
direct allocation
page read and write
5920000
heap
page read and write
32DA000
heap
page read and write
2DA0000
direct allocation
page read and write
58EC000
heap
page read and write
2DFA000
direct allocation
page read and write
43D5000
direct allocation
page read and write
5954000
heap
page read and write
4D63000
heap
page read and write
46E7000
direct allocation
page read and write
28B1000
heap
page read and write
43CD000
stack
page read and write
4AF2000
heap
page read and write
574C000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
7B5A000
direct allocation
page read and write
5349000
heap
page read and write
50EA000
heap
page read and write
5040000
heap
page read and write
3DA4000
direct allocation
page read and write
4266000
direct allocation
page read and write
288A000
heap
page read and write
70A6000
direct allocation
page read and write
4D3F000
heap
page read and write
473A000
direct allocation
page read and write
53E7000
heap
page read and write
52D8000
heap
page read and write
71EC000
direct allocation
page read and write
3224000
direct allocation
page read and write
4D63000
heap
page read and write
50FD000
heap
page read and write
58F4000
heap
page read and write
45FC000
direct allocation
page read and write
4AE5000
heap
page read and write
32BD000
heap
page read and write
2C16000
direct allocation
page read and write
5376000
heap
page read and write
79EC000
direct allocation
page read and write
5323000
heap
page read and write
6FB6000
direct allocation
page read and write
5116000
heap
page read and write
58F4000
heap
page read and write
37EA000
direct allocation
page read and write
32BF000
heap
page read and write
43B0000
direct allocation
page read and write
28B5000
heap
page read and write
58EC000
heap
page read and write
2071000
unkown
page read and write
5A52000
heap
page read and write
3AAC000
direct allocation
page read and write
36CA000
direct allocation
page read and write
4D4A000
heap
page read and write
32D2000
heap
page read and write
28F4000
direct allocation
page read and write
4AD1000
heap
page read and write
7254000
direct allocation
page read and write
297D000
stack
page read and write
3C08000
direct allocation
page read and write
3043000
direct allocation
page read and write
327E000
direct allocation
page read and write
58EC000
heap
page read and write
311D000
direct allocation
page read and write
58C8000
heap
page read and write
700A000
direct allocation
page read and write
4692000
direct allocation
page read and write
58F4000
heap
page read and write
722C000
direct allocation
page read and write
7A74000
direct allocation
page read and write
3850000
direct allocation
page read and write
4D5E000
heap
page read and write
5071000
heap
page read and write
384C000
direct allocation
page read and write
7094000
direct allocation
page read and write
71AE000
direct allocation
page read and write
5323000
heap
page read and write
50EA000
heap
page read and write
4D53000
heap
page read and write
6946000
direct allocation
page read and write
532C000
heap
page read and write
58E8000
heap
page read and write
2E06000
direct allocation
page read and write
2BDE000
direct allocation
page read and write
27E0000
direct allocation
page read and write
4284000
direct allocation
page read and write
4D27000
heap
page read and write
69F6000
direct allocation
page read and write
4D4A000
heap
page read and write
3756000
direct allocation
page read and write
555F000
heap
page read and write
7AEE000
direct allocation
page read and write
58D9000
heap
page read and write
4DBD000
heap
page read and write
5C54000
direct allocation
page read and write
2892000
heap
page read and write
510E000
heap
page read and write
55B4000
heap
page read and write
7B48000
direct allocation
page read and write
2A70000
heap
page read and write
5D01000
direct allocation
page read and write
5116000
heap
page read and write
6C5E000
direct allocation
page read and write
32D9000
heap
page read and write
301E000
direct allocation
page read and write
42BA000
direct allocation
page read and write
52E2000
heap
page read and write
32E0000
heap
page read and write
5653000
heap
page read and write
50DB000
heap
page read and write
28BA000
heap
page read and write
2DB6000
direct allocation
page read and write
4ACD000
heap
page read and write
71A4000
direct allocation
page read and write
471E000
direct allocation
page read and write
4ADC000
heap
page read and write
52C4000
heap
page read and write
69C8000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
4D10000
heap
page read and write
289C000
heap
page read and write
7458000
direct allocation
page read and write
2D06000
direct allocation
page read and write
32F2000
heap
page read and write
72FA000
direct allocation
page read and write
38EE000
direct allocation
page read and write
58D8000
heap
page read and write
402E000
direct allocation
page read and write
29E8000
heap
page read and write
3864000
direct allocation
page read and write
2BBC000
direct allocation
page read and write
2BE8000
direct allocation
page read and write
6AC8000
direct allocation
page read and write
50EA000
heap
page read and write
52C5000
heap
page read and write
507F000
heap
page read and write
2A61000
heap
page read and write
2D72000
direct allocation
page read and write
3082000
direct allocation
page read and write
5B37000
heap
page read and write
35B2000
direct allocation
page read and write
295A000
direct allocation
page read and write
3D36000
direct allocation
page read and write
3CB4000
direct allocation
page read and write
4444000
direct allocation
page read and write
6B36000
direct allocation
page read and write
5632000
heap
page read and write
28B5000
heap
page read and write
5660000
heap
page read and write
7024000
direct allocation
page read and write
719A000
direct allocation
page read and write
C0D000
stack
page read and write
568C000
heap
page read and write
43CF000
direct allocation
page read and write
4D53000
heap
page read and write
53D7000
heap
page read and write
6FCA000
direct allocation
page read and write
28BE000
heap
page read and write
2D3C000
direct allocation
page read and write
4826000
direct allocation
page read and write
58E8000
heap
page read and write
746A000
direct allocation
page read and write
782A000
direct allocation
page read and write
4278000
direct allocation
page read and write
4D4A000
heap
page read and write
7708000
direct allocation
page read and write
2BF8000
direct allocation
page read and write
312E000
direct allocation
page read and write
725A000
direct allocation
page read and write
2E36000
direct allocation
page read and write
71D8000
direct allocation
page read and write
38C8000
direct allocation
page read and write
3BE6000
direct allocation
page read and write
510A000
heap
page read and write
6DFC000
direct allocation
page read and write
51AC000
heap
page read and write
6E4A000
direct allocation
page read and write
6B6C000
direct allocation
page read and write
7E64000
direct allocation
page read and write
7CE8000
direct allocation
page read and write
6906000
direct allocation
page read and write
4D10000
heap
page read and write
142A000
unkown
page readonly
3208000
direct allocation
page read and write
58F4000
heap
page read and write
4468000
direct allocation
page read and write
4AB9000
heap
page read and write
43BC000
direct allocation
page read and write
75B8000
direct allocation
page read and write
4D0D000
heap
page read and write
7BDA000
direct allocation
page read and write
30C0000
heap
page read and write
4D1D000
heap
page read and write
4A75000
heap
page read and write
2EF0000
direct allocation
page read and write
2880000
heap
page read and write
7E92000
direct allocation
page read and write
28BE000
heap
page read and write
3C68000
direct allocation
page read and write
6B86000
direct allocation
page read and write
527C000
heap
page read and write
4AEB000
heap
page read and write
7A2C000
direct allocation
page read and write
3F50000
direct allocation
page read and write
4D1A000
heap
page read and write
6E60000
direct allocation
page read and write
5562000
heap
page read and write
30AA000
direct allocation
page read and write
56FB000
direct allocation
page read and write
2F8E000
direct allocation
page read and write
324A000
direct allocation
page read and write
27F9000
heap
page read and write
990000
heap
page read and write
4ACC000
heap
page read and write
50EA000
heap
page read and write
5707000
heap
page read and write
7592000
direct allocation
page read and write
3884000
direct allocation
page read and write
4CE4000
heap
page read and write
4D0F000
heap
page read and write
39C8000
direct allocation
page read and write
77FC000
direct allocation
page read and write
2850000
direct allocation
page read and write
6A2E000
direct allocation
page read and write
7E7E000
direct allocation
page read and write
3184000
direct allocation
page read and write
762A000
direct allocation
page read and write
69A6000
direct allocation
page read and write
58EC000
heap
page read and write
5A82000
heap
page read and write
7774000
direct allocation
page read and write
180F000
unkown
page read and write
5C57000
direct allocation
page read and write
40EC000
direct allocation
page read and write
2C85000
direct allocation
page read and write
6926000
direct allocation
page read and write
302E000
direct allocation
page read and write
58EC000
heap
page read and write
6E10000
direct allocation
page read and write
7D54000
direct allocation
page read and write
C8E000
direct allocation
page read and write
58EC000
heap
page read and write
66A4000
direct allocation
page read and write
68F6000
direct allocation
page read and write
7B66000
direct allocation
page read and write
2CAA000
direct allocation
page read and write
5A62000
heap
page read and write
2874000
heap
page read and write
4DA7000
heap
page read and write
4D77000
heap
page read and write
5116000
heap
page read and write
4D4A000
heap
page read and write
4D2F000
heap
page read and write
50EA000
heap
page read and write
32DB000
heap
page read and write
50EA000
heap
page read and write
7C74000
direct allocation
page read and write
57E0000
heap
page read and write
4262000
direct allocation
page read and write
7034000
direct allocation
page read and write
4AA9000
heap
page read and write
510A000
heap
page read and write
7AE8000
direct allocation
page read and write
76FA000
direct allocation
page read and write
4ACC000
heap
page read and write
32FC000
heap
page read and write
6C90000
direct allocation
page read and write
6BF4000
direct allocation
page read and write
6BEE000
direct allocation
page read and write
58EC000
heap
page read and write
202E000
unkown
page read and write
2A70000
heap
page read and write
2A70000
heap
page read and write
74D0000
direct allocation
page read and write
2874000
heap
page read and write
2B01000
direct allocation
page read and write
58C8000
heap
page read and write
7B80000
direct allocation
page read and write
58D8000
heap
page read and write
52DE000
heap
page read and write
4761000
direct allocation
page read and write
5A4F000
heap
page read and write
6F16000
direct allocation
page read and write
6CFC000
direct allocation
page read and write
57E0000
heap
page read and write
7A10000
direct allocation
page read and write
32CC000
direct allocation
page read and write
58B9000
heap
page read and write
56EF000
heap
page read and write
6FF8000
direct allocation
page read and write
4CD4000
heap
page read and write
770C000
direct allocation
page read and write
28B1000
heap
page read and write
6EB8000
direct allocation
page read and write
2D82000
direct allocation
page read and write
58B9000
heap
page read and write
4AEB000
heap
page read and write
4AA7000
heap
page read and write
2F64000
direct allocation
page read and write
73F6000
direct allocation
page read and write
58E8000
heap
page read and write
7A68000
direct allocation
page read and write
5678000
heap
page read and write
2A5C000
heap
page read and write
57FD000
heap
page read and write
4B4A000
heap
page read and write
4733000
direct allocation
page read and write
6C14000
direct allocation
page read and write
72B4000
direct allocation
page read and write
72B4000
direct allocation
page read and write
58E8000
heap
page read and write
2892000
heap
page read and write
5550000
trusted library allocation
page read and write
5304000
heap
page read and write
4AE0000
heap
page read and write
2E14000
direct allocation
page read and write
590C000
heap
page read and write
725C000
direct allocation
page read and write
510E000
heap
page read and write
58EC000
heap
page read and write
39F4000
direct allocation
page read and write
2A6C000
heap
page read and write
32DD000
heap
page read and write
4D4A000
heap
page read and write
58C8000
heap
page read and write
4AAE000
heap
page read and write
5056000
heap
page read and write
7340000
direct allocation
page read and write
287B000
heap
page read and write
74BC000
direct allocation
page read and write
4D65000
heap
page read and write
3141000
direct allocation
page read and write
5304000
heap
page read and write
70B8000
direct allocation
page read and write
306A000
direct allocation
page read and write
6FE6000
direct allocation
page read and write
510A000
heap
page read and write
2B36000
direct allocation
page read and write
5D1A000
direct allocation
page read and write
4AF3000
heap
page read and write
4D3F000
heap
page read and write
76E0000
direct allocation
page read and write
32F2000
heap
page read and write
4676000
direct allocation
page read and write
71C0000
direct allocation
page read and write
721A000
direct allocation
page read and write
35D2000
direct allocation
page read and write
7AA0000
direct allocation
page read and write
7A60000
direct allocation
page read and write
6EC0000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
6B98000
direct allocation
page read and write
7532000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
545E000
heap
page read and write
4AE0000
heap
page read and write
58B9000
heap
page read and write
473C000
direct allocation
page read and write
2C1A000
direct allocation
page read and write
750C000
direct allocation
page read and write
22BFF000
stack
page read and write
2926000
direct allocation
page read and write
2FB6000
direct allocation
page read and write
25FE000
stack
page read and write
7098000
direct allocation
page read and write
3290000
direct allocation
page read and write
2F76000
direct allocation
page read and write
7A78000
direct allocation
page read and write
4CE4000
heap
page read and write
50CF000
heap
page read and write
7AB8000
direct allocation
page read and write
5742000
direct allocation
page read and write
423C000
direct allocation
page read and write
5680000
heap
page read and write
2893000
heap
page read and write
6F92000
direct allocation
page read and write
5671000
heap
page read and write
3FD2000
direct allocation
page read and write
28AE000
heap
page read and write
58F4000
heap
page read and write
58F4000
heap
page read and write
4AC6000
heap
page read and write
4D4A000
heap
page read and write
73C000
stack
page read and write
79F8000
direct allocation
page read and write
4AAA000
heap
page read and write
30D6000
direct allocation
page read and write
772D000
direct allocation
page read and write
3588000
direct allocation
page read and write
5AD1000
heap
page read and write
7CDA000
direct allocation
page read and write
3C1E000
direct allocation
page read and write
4D27000
heap
page read and write
6DFC000
direct allocation
page read and write
3B40000
direct allocation
page read and write
75A2000
direct allocation
page read and write
4ADC000
heap
page read and write
6E02000
direct allocation
page read and write
3F14000
direct allocation
page read and write
581C000
heap
page read and write
2071000
unkown
page read and write
4355000
direct allocation
page read and write
4D4A000
heap
page read and write
3D7C000
direct allocation
page read and write
58E8000
heap
page read and write
31FB000
direct allocation
page read and write
5348000
heap
page read and write
428A000
direct allocation
page read and write
1A7A000
unkown
page readonly
4D3F000
heap
page read and write
6D7C000
direct allocation
page read and write
3F02000
direct allocation
page read and write
741A000
direct allocation
page read and write
502B000
heap
page read and write
4836000
direct allocation
page read and write
30D2000
direct allocation
page read and write
5463000
heap
page read and write
58EC000
heap
page read and write
4750000
remote allocation
page read and write
38D6000
direct allocation
page read and write
70FE000
direct allocation
page read and write
28B3000
heap
page read and write
7EA2000
direct allocation
page read and write
5847000
heap
page read and write
2E4E000
direct allocation
page read and write
2893000
heap
page read and write
29A0000
direct allocation
page read and write
77EE000
direct allocation
page read and write
2992000
direct allocation
page read and write
35DE000
direct allocation
page read and write
28A3000
heap
page read and write
6F80000
direct allocation
page read and write
534B000
heap
page read and write
5116000
heap
page read and write
74F4000
direct allocation
page read and write
58F4000
heap
page read and write
2880000
heap
page read and write
3EF4000
direct allocation
page read and write
52FD000
heap
page read and write
2CEC000
direct allocation
page read and write
36B8000
direct allocation
page read and write
2DC2000
direct allocation
page read and write
28A3000
heap
page read and write
58EC000
heap
page read and write
4D9A000
heap
page read and write
510E000
heap
page read and write
4D20000
heap
page read and write
6CFE000
direct allocation
page read and write
52D7000
heap
page read and write
78BC000
direct allocation
page read and write
6E22000
direct allocation
page read and write
4AAE000
heap
page read and write
32D9000
heap
page read and write
3294000
direct allocation
page read and write
4D3F000
heap
page read and write
4DA8000
heap
page read and write
70CC000
direct allocation
page read and write
58B9000
heap
page read and write
427B000
direct allocation
page read and write
C90000
heap
page read and write
4AA7000
heap
page read and write
4ABD000
heap
page read and write
288A000
heap
page read and write
749A000
direct allocation
page read and write
7B9A000
direct allocation
page read and write
5304000
heap
page read and write
458E000
direct allocation
page read and write
6976000
direct allocation
page read and write
6948000
direct allocation
page read and write
4A6B000
heap
page read and write
58D8000
heap
page read and write
4AAA000
heap
page read and write
28A6000
heap
page read and write
3DAE000
direct allocation
page read and write
4D4A000
heap
page read and write
2A67000
heap
page read and write
1CC3000
unkown
page readonly
6ADE000
direct allocation
page read and write
4ACD000
heap
page read and write
2972000
direct allocation
page read and write
510A000
heap
page read and write
4D4A000
heap
page read and write
47AD000
direct allocation
page read and write
2EA8000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
2D30000
direct allocation
page read and write
2AC9000
direct allocation
page read and write
4D53000
heap
page read and write
1C94000
unkown
page write copy
7978000
direct allocation
page read and write
4D3F000
heap
page read and write
32C1000
heap
page read and write
4318000
direct allocation
page read and write
3680000
direct allocation
page read and write
7698000
direct allocation
page read and write
2DE6000
direct allocation
page read and write
51E1000
heap
page read and write
742A000
direct allocation
page read and write
4D53000
heap
page read and write
32D9000
heap
page read and write
2A86000
heap
page read and write
1DB0000
direct allocation
page read and write
4D3F000
heap
page read and write
555C000
heap
page read and write
52C9000
heap
page read and write
4D3F000
heap
page read and write
2892000
heap
page read and write
4D25000
heap
page read and write
6956000
direct allocation
page read and write
5327000
heap
page read and write
289C000
heap
page read and write
5550000
trusted library allocation
page read and write
4333000
direct allocation
page read and write
2E9F000
direct allocation
page read and write
289B000
heap
page read and write
58F4000
heap
page read and write
4D29000
heap
page read and write
58E8000
heap
page read and write
5550000
trusted library allocation
page read and write
2DBC000
direct allocation
page read and write
58B9000
heap
page read and write
6C10000
direct allocation
page read and write
58D8000
heap
page read and write
6ECC000
direct allocation
page read and write
4D3F000
heap
page read and write
32D5000
heap
page read and write
58D8000
heap
page read and write
761C000
direct allocation
page read and write
2871000
heap
page read and write
7A5A000
direct allocation
page read and write
6F38000
direct allocation
page read and write
58D8000
heap
page read and write
53A7000
heap
page read and write
58C9000
heap
page read and write
2DD0000
direct allocation
page read and write
50FF000
heap
page read and write
28BE000
heap
page read and write
52C5000
heap
page read and write
532C000
heap
page read and write
4D4A000
heap
page read and write
7A38000
direct allocation
page read and write
4D63000
heap
page read and write
28AE000
heap
page read and write
409B000
direct allocation
page read and write
4744000
direct allocation
page read and write
5C11000
direct allocation
page read and write
43F6000
direct allocation
page read and write
56D0000
direct allocation
page read and write
53BD000
heap
page read and write
781A000
direct allocation
page read and write
50FA000
heap
page read and write
7D44000
direct allocation
page read and write
28AF000
heap
page read and write
36AA000
direct allocation
page read and write
360C000
direct allocation
page read and write
36D9000
direct allocation
page read and write
27F9000
heap
page read and write
7026000
direct allocation
page read and write
4D27000
heap
page read and write
5313000
heap
page read and write
3080000
direct allocation
page read and write
3F76000
direct allocation
page read and write
7462000
direct allocation
page read and write
6D2C000
direct allocation
page read and write
7E2E000
direct allocation
page read and write
742C000
direct allocation
page read and write
6D5E000
direct allocation
page read and write
42E0000
direct allocation
page read and write
7650000
direct allocation
page read and write
2813000
heap
page read and write
76C0000
direct allocation
page read and write
28B6000
heap
page read and write
75EC000
direct allocation
page read and write
29B9000
direct allocation
page read and write
3876000
direct allocation
page read and write
7069000
direct allocation
page read and write
5A52000
heap
page read and write
2ECA000
direct allocation
page read and write
4AAB000
heap
page read and write
4D27000
heap
page read and write
25429000
direct allocation
page read and write
4CE5000
heap
page read and write
7B24000
direct allocation
page read and write
4AA7000
heap
page read and write
58D8000
heap
page read and write
1418000
unkown
page read and write
6C46000
direct allocation
page read and write
28AB000
heap
page read and write
6C38000
direct allocation
page read and write
75B2000
direct allocation
page read and write
4D27000
heap
page read and write
45AA000
direct allocation
page read and write
4340000
direct allocation
page read and write
2B4A000
direct allocation
page read and write
4D45000
heap
page read and write
5116000
heap
page read and write
4D3F000
heap
page read and write
4D3F000
heap
page read and write
1846000
unkown
page readonly
3069000
direct allocation
page read and write
6B72000
direct allocation
page read and write
385A000
direct allocation
page read and write
4712000
direct allocation
page read and write
5C86000
heap
page read and write
2CB2000
direct allocation
page read and write
5116000
heap
page read and write
779A000
direct allocation
page read and write
50EA000
heap
page read and write
50EA000
heap
page read and write
69E6000
direct allocation
page read and write
56A1000
heap
page read and write
432D000
direct allocation
page read and write
583C000
heap
page read and write
2C3C000
direct allocation
page read and write
4AFC000
heap
page read and write
2A6C000
heap
page read and write
4D63000
heap
page read and write
52D7000
heap
page read and write
3E14000
direct allocation
page read and write
55B4000
heap
page read and write
4D4A000
heap
page read and write
2900000
direct allocation
page read and write
4D27000
heap
page read and write
41CE000
direct allocation
page read and write
58F4000
heap
page read and write
6DDC000
direct allocation
page read and write
23F0000
heap
page read and write
510A000
heap
page read and write
43C2000
direct allocation
page read and write
4746000
direct allocation
page read and write
4AC6000
heap
page read and write
565C000
heap
page read and write
76E4000
direct allocation
page read and write
4D77000
heap
page read and write
2CA6000
direct allocation
page read and write
4AF0000
heap
page read and write
22FD000
stack
page read and write
47C5000
direct allocation
page read and write
3BBE000
direct allocation
page read and write
52DA000
heap
page read and write
6A36000
direct allocation
page read and write
2D5E000
direct allocation
page read and write
475E000
direct allocation
page read and write
3F88000
direct allocation
page read and write
3C3E000
direct allocation
page read and write
30E8000
direct allocation
page read and write
7D94000
direct allocation
page read and write
58F4000
heap
page read and write
4D67000
heap
page read and write
4ACD000
heap
page read and write
7CFC000
direct allocation
page read and write
7C46000
direct allocation
page read and write
2A66000
heap
page read and write
5C7A000
direct allocation
page read and write
71DA000
direct allocation
page read and write
23D0000
heap
page read and write
289B000
heap
page read and write
44FA000
direct allocation
page read and write
2D0A000
direct allocation
page read and write
359A000
direct allocation
page read and write
73D2000
direct allocation
page read and write
7784000
direct allocation
page read and write
3D56000
direct allocation
page read and write
510A000
heap
page read and write
5CC4000
direct allocation
page read and write
2083000
unkown
page read and write
2A93000
heap
page read and write
5291000
heap
page read and write
2C80000
direct allocation
page read and write
27F0000
direct allocation
page read and write
47D6000
direct allocation
page read and write
53D7000
heap
page read and write
52D9000
heap
page read and write
323F000
heap
page read and write
5083000
heap
page read and write
2D20000
direct allocation
page read and write
2874000
heap
page read and write
6C04000
direct allocation
page read and write
4432000
direct allocation
page read and write
4664000
direct allocation
page read and write
35C8000
direct allocation
page read and write
141F000
unkown
page read and write
7E86000
direct allocation
page read and write
4480000
heap
page read and write
58E5000
heap
page read and write
4AAB000
heap
page read and write
4D7B000
heap
page read and write
5279000
heap
page read and write
2E5C000
direct allocation
page read and write
42F1000
direct allocation
page read and write
58B9000
heap
page read and write
3768000
direct allocation
page read and write
3A24000
direct allocation
page read and write
4D1D000
heap
page read and write
52C4000
heap
page read and write
58E8000
heap
page read and write
7BC8000
direct allocation
page read and write
58F4000
heap
page read and write
4D4A000
heap
page read and write
24BD000
stack
page read and write
32D9000
heap
page read and write
7D22000
direct allocation
page read and write
28AF000
heap
page read and write
5A79000
heap
page read and write
58F4000
heap
page read and write
4D0F000
heap
page read and write
2892000
heap
page read and write
55A8000
heap
page read and write
5A4F000
heap
page read and write
5116000
heap
page read and write
47DB000
direct allocation
page read and write
4D54000
heap
page read and write
7AC8000
direct allocation
page read and write
4AAE000
heap
page read and write
58B9000
heap
page read and write
39A2000
direct allocation
page read and write
C08000
direct allocation
page read and write
6DEA000
direct allocation
page read and write
5089000
heap
page read and write
532D000
heap
page read and write
4458000
direct allocation
page read and write
702E000
direct allocation
page read and write
6CEC000
direct allocation
page read and write
4D15000
heap
page read and write
6B3C000
direct allocation
page read and write
52D7000
heap
page read and write
4702000
direct allocation
page read and write
58DE000
heap
page read and write
4AC6000
heap
page read and write
52A5000
heap
page read and write
58C9000
heap
page read and write
7026000
direct allocation
page read and write
372A000
direct allocation
page read and write
4280000
direct allocation
page read and write
2874000
heap
page read and write
5343000
heap
page read and write
3A12000
direct allocation
page read and write
2C26000
direct allocation
page read and write
5054000
heap
page read and write
417A000
direct allocation
page read and write
2C0C000
direct allocation
page read and write
6FF6000
direct allocation
page read and write
37F2000
direct allocation
page read and write
6D26000
direct allocation
page read and write
1100000
unkown
page execute read
45B2000
direct allocation
page read and write
756B000
direct allocation
page read and write
7066000
direct allocation
page read and write
4AA9000
heap
page read and write
4AC6000
heap
page read and write
2D98000
direct allocation
page read and write
7780000
direct allocation
page read and write
29C6000
direct allocation
page read and write
4B3D000
heap
page read and write
79E4000
direct allocation
page read and write
52E7000
heap
page read and write
66D8000
direct allocation
page read and write
7688000
direct allocation
page read and write
2982000
direct allocation
page read and write
32FD000
heap
page read and write
4D77000
heap
page read and write
284B000
direct allocation
page read and write
2E96000
direct allocation
page read and write
6EE6000
direct allocation
page read and write
7806000
direct allocation
page read and write
6894000
direct allocation
page read and write
2ED5000
direct allocation
page read and write
7E52000
direct allocation
page read and write
58F4000
heap
page read and write
422E000
direct allocation
page read and write
58C8000
heap
page read and write
325A000
direct allocation
page read and write
4D63000
heap
page read and write
4D4A000
heap
page read and write
7608000
direct allocation
page read and write
7730000
direct allocation
page read and write
2956000
direct allocation
page read and write
4D6B000
heap
page read and write
4D2B000
heap
page read and write
5860000
trusted library allocation
page read and write
5D04000
direct allocation
page read and write
2D26000
direct allocation
page read and write
2EFA000
direct allocation
page read and write
2C47000
direct allocation
page read and write
2A70000
heap
page read and write
670E000
direct allocation
page read and write
2880000
heap
page read and write
43BE000
direct allocation
page read and write
3A4E000
direct allocation
page read and write
58C8000
heap
page read and write
4D15000
heap
page read and write
29F3000
heap
page read and write
28BD000
heap
page read and write
4D4A000
heap
page read and write
4AA7000
heap
page read and write
366E000
direct allocation
page read and write
58C8000
heap
page read and write
43CA000
direct allocation
page read and write
765A000
direct allocation
page read and write
58C8000
heap
page read and write
50DB000
heap
page read and write
32DB000
heap
page read and write
7178000
direct allocation
page read and write
2E3C000
direct allocation
page read and write
58C8000
heap
page read and write
4D4A000
heap
page read and write
2C1A000
direct allocation
page read and write
2874000
heap
page read and write
4B07000
heap
page read and write
4A7C000
heap
page read and write
58C8000
heap
page read and write
58E8000
heap
page read and write
2AC0000
heap
page read and write
7EBE000
direct allocation
page read and write
7262000
direct allocation
page read and write
5371000
heap
page read and write
4790000
direct allocation
page read and write
4D3F000
heap
page read and write
32FC000
heap
page read and write
287E000
direct allocation
page read and write
2F8A000
direct allocation
page read and write
6DC4000
direct allocation
page read and write
1109000
unkown
page execute read
6D24000
direct allocation
page read and write
5C2F000
direct allocation
page read and write
583C000
heap
page read and write
305E000
direct allocation
page read and write
4D27000
heap
page read and write
247E000
stack
page read and write
231F000
stack
page read and write
58C8000
heap
page read and write
50FD000
heap
page read and write
2CA0000
direct allocation
page read and write
4ABF000
heap
page read and write
78AA000
direct allocation
page read and write
43E8000
direct allocation
page read and write
7DF8000
direct allocation
page read and write
731C000
direct allocation
page read and write
2C18000
direct allocation
page read and write
4112000
direct allocation
page read and write
6D33000
direct allocation
page read and write
418C000
direct allocation
page read and write
5415000
heap
page read and write
4D1E000
heap
page read and write
4286000
direct allocation
page read and write
684A000
direct allocation
page read and write
2958000
direct allocation
page read and write
4D3F000
heap
page read and write
7AFA000
direct allocation
page read and write
4A7C000
heap
page read and write
CA0000
heap
page read and write
3672000
direct allocation
page read and write
2D10000
direct allocation
page read and write
2A9F000
heap
page read and write
3BAA000
direct allocation
page read and write
289C000
heap
page read and write
58C8000
heap
page read and write
6AC2000
direct allocation
page read and write
71B6000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
4756000
direct allocation
page read and write
2E8E000
direct allocation
page read and write
77B4000
direct allocation
page read and write
5868000
heap
page read and write
4D27000
heap
page read and write
55CE000
stack
page read and write
2A70000
heap
page read and write
2CA0000
direct allocation
page read and write
7502000
direct allocation
page read and write
4218000
direct allocation
page read and write
3920000
direct allocation
page read and write
7BD0000
direct allocation
page read and write
32A6000
direct allocation
page read and write
4240000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
45E2000
direct allocation
page read and write
75C8000
direct allocation
page read and write
4A6B000
heap
page read and write
47DE000
direct allocation
page read and write
5689000
heap
page read and write
5304000
heap
page read and write
58F4000
heap
page read and write
74CC000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
776C000
direct allocation
page read and write
47C8000
direct allocation
page read and write
43C5000
direct allocation
page read and write
50FA000
heap
page read and write
463E000
direct allocation
page read and write
42C5000
direct allocation
page read and write
6E94000
direct allocation
page read and write
7E9A000
direct allocation
page read and write
2DC4000
direct allocation
page read and write
52C4000
heap
page read and write
318A000
direct allocation
page read and write
532D000
heap
page read and write
2D42000
direct allocation
page read and write
2A83000
heap
page read and write
28A3000
heap
page read and write
4D27000
heap
page read and write
3ABA000
direct allocation
page read and write
785A000
direct allocation
page read and write
4D13000
heap
page read and write
4AC6000
heap
page read and write
3FE4000
direct allocation
page read and write
7662000
direct allocation
page read and write
510E000
heap
page read and write
4AAB000
heap
page read and write
4D3F000
heap
page read and write
4D3F000
heap
page read and write
4D27000
heap
page read and write
78C6000
direct allocation
page read and write
58C8000
heap
page read and write
58D8000
heap
page read and write
32FC000
heap
page read and write
2D74000
direct allocation
page read and write
790C000
direct allocation
page read and write
5305000
heap
page read and write
3D48000
direct allocation
page read and write
50DB000
heap
page read and write
67F8000
direct allocation
page read and write
582B000
heap
page read and write
7DDE000
direct allocation
page read and write
7ED4000
direct allocation
page read and write
510A000
heap
page read and write
4823000
direct allocation
page read and write
532C000
heap
page read and write
3562000
direct allocation
page read and write
2DB0000
direct allocation
page read and write
6CC8000
direct allocation
page read and write
2A83000
heap
page read and write
7846000
direct allocation
page read and write
118A000
unkown
page execute read
700E000
direct allocation
page read and write
4D0E000
heap
page read and write
55A8000
heap
page read and write
7DAE000
direct allocation
page read and write
292E000
direct allocation
page read and write
7048000
direct allocation
page read and write
532C000
heap
page read and write
2C20000
direct allocation
page read and write
30D0000
direct allocation
page execute and read and write
7738000
direct allocation
page read and write
741A000
direct allocation
page read and write
4CD4000
heap
page read and write
7724000
direct allocation
page read and write
2A82000
heap
page read and write
4D53000
heap
page read and write
2C0A000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
70BA000
direct allocation
page read and write
6BCE000
direct allocation
page read and write
6F92000
direct allocation
page read and write
4D63000
heap
page read and write
58E8000
heap
page read and write
5716000
direct allocation
page read and write
7834000
direct allocation
page read and write
58C8000
heap
page read and write
784E000
direct allocation
page read and write
794A000
direct allocation
page read and write
4ABF000
heap
page read and write
75B6000
direct allocation
page read and write
50EA000
heap
page read and write
28A5000
heap
page read and write
400A000
direct allocation
page read and write
2FA2000
direct allocation
page read and write
5340000
heap
page read and write
37CC000
direct allocation
page read and write
763C000
direct allocation
page read and write
2C1E000
direct allocation
page read and write
6DA2000
direct allocation
page read and write
3A3B000
direct allocation
page read and write
5BF9000
direct allocation
page read and write
555C000
heap
page read and write
561C000
heap
page read and write
289A000
heap
page read and write
7762000
direct allocation
page read and write
532D000
heap
page read and write
7AB4000
direct allocation
page read and write
6BC4000
direct allocation
page read and write
2893000
heap
page read and write
5914000
heap
page read and write
52D8000
heap
page read and write
36AE000
direct allocation
page read and write
3D92000
direct allocation
page read and write
2C9B000
direct allocation
page read and write
7A2C000
direct allocation
page read and write
7056000
direct allocation
page read and write
27DE000
heap
page read and write
38EA000
direct allocation
page read and write
3E5C000
direct allocation
page read and write
6ED2000
direct allocation
page read and write
2FB4000
direct allocation
page read and write
78C4000
direct allocation
page read and write
567B000
heap
page read and write
4532000
direct allocation
page read and write
35BA000
direct allocation
page read and write
4EBD000
stack
page read and write
2BDA000
direct allocation
page read and write
4D53000
heap
page read and write
2CB6000
direct allocation
page read and write
32C1000
direct allocation
page read and write
70CA000
direct allocation
page read and write
2E0A000
direct allocation
page read and write
6F1A000
direct allocation
page read and write
4D4A000
heap
page read and write
4A6B000
heap
page read and write
7352000
direct allocation
page read and write
72E6000
direct allocation
page read and write
4D36000
heap
page read and write
2A91000
heap
page read and write
7162000
direct allocation
page read and write
4D3F000
heap
page read and write
30A0000
direct allocation
page read and write
457C000
direct allocation
page read and write
55A7000
heap
page read and write
3A06000
direct allocation
page read and write
39DA000
direct allocation
page read and write
58F4000
heap
page read and write
52C5000
heap
page read and write
6B34000
direct allocation
page read and write
4126000
direct allocation
page read and write
707C000
direct allocation
page read and write
7152000
direct allocation
page read and write
72D4000
direct allocation
page read and write
288A000
heap
page read and write
2240000
direct allocation
page read and write
7488000
direct allocation
page read and write
66C6000
direct allocation
page read and write
2436000
heap
page read and write
4D10000
heap
page read and write
28AF000
heap
page read and write
4D6B000
heap
page read and write
4CD1000
heap
page read and write
5CB8000
direct allocation
page read and write
4D89000
heap
page read and write
78EE000
direct allocation
page read and write
4D53000
heap
page read and write
6E66000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
6B16000
direct allocation
page read and write
4D3F000
heap
page read and write
3B86000
direct allocation
page read and write
2A6C000
heap
page read and write
7A82000
direct allocation
page read and write
47C8000
direct allocation
page read and write
2DA4000
direct allocation
page read and write
2946000
direct allocation
page read and write
7188000
direct allocation
page read and write
4A81000
heap
page read and write
6BA2000
direct allocation
page read and write
4D3F000
heap
page read and write
7A84000
direct allocation
page read and write
6E3A000
direct allocation
page read and write
3996000
direct allocation
page read and write
58F4000
heap
page read and write
4D17000
heap
page read and write
6A26000
direct allocation
page read and write
58B9000
heap
page read and write
4B56000
heap
page read and write
326E000
direct allocation
page read and write
3CD6000
direct allocation
page read and write
7ADA000
direct allocation
page read and write
7900000
direct allocation
page read and write
4ACD000
heap
page read and write
6F3A000
direct allocation
page read and write
3902000
direct allocation
page read and write
47D8000
direct allocation
page read and write
58C9000
heap
page read and write
4D66000
heap
page read and write
3828000
direct allocation
page read and write
3D5A000
direct allocation
page read and write
4ACD000
heap
page read and write
68F3000
direct allocation
page read and write
7250000
direct allocation
page read and write
2802000
heap
page read and write
4AE0000
heap
page read and write
3688000
direct allocation
page read and write
3CFE000
direct allocation
page read and write
5116000
heap
page read and write
6A56000
direct allocation
page read and write
2C38000
direct allocation
page read and write
7592000
direct allocation
page read and write
28B6000
heap
page read and write
58D8000
heap
page read and write
2258000
direct allocation
page read and write
540E000
heap
page read and write
47D5000
direct allocation
page read and write
2D52000
direct allocation
page read and write
1C97000
unkown
page write copy
4D1A000
heap
page read and write
24D70000
direct allocation
page read and write
73D2000
direct allocation
page read and write
37DA000
direct allocation
page read and write
52C1000
heap
page read and write
7B12000
direct allocation
page read and write
32FC000
heap
page read and write
4D4A000
heap
page read and write
58E8000
heap
page read and write
5332000
heap
page read and write
29C2000
direct allocation
page read and write
55B1000
heap
page read and write
7290000
direct allocation
page read and write
6B00000
direct allocation
page read and write
5102000
heap
page read and write
45D0000
direct allocation
page read and write
52E4000
heap
page read and write
2F92000
direct allocation
page read and write
2C02000
direct allocation
page read and write
5307000
heap
page read and write
46E1000
direct allocation
page read and write
510E000
heap
page read and write
5038000
heap
page read and write
6C0C000
direct allocation
page read and write
78D5000
direct allocation
page read and write
32D2000
heap
page read and write
7AFA000
direct allocation
page read and write
5C43000
direct allocation
page read and write
2F51000
direct allocation
page read and write
6AEC000
direct allocation
page read and write
32D5000
heap
page read and write
5728000
heap
page read and write
783C000
direct allocation
page read and write
70D8000
direct allocation
page read and write
484A000
direct allocation
page read and write
58C9000
heap
page read and write
7086000
direct allocation
page read and write
28BC000
direct allocation
page read and write
37B8000
direct allocation
page read and write
2A71000
heap
page read and write
4ACD000
heap
page read and write
28AE000
heap
page read and write
38B6000
direct allocation
page read and write
2FF4000
direct allocation
page read and write
4A6B000
heap
page read and write
3200000
heap
page read and write
496A000
direct allocation
page read and write
54A7000
heap
page read and write
3618000
direct allocation
page read and write
7E2E000
direct allocation
page read and write
2900000
remote allocation
page read and write
4D4A000
heap
page read and write
50FA000
heap
page read and write
3E3C000
direct allocation
page read and write
3223000
heap
page read and write
58EC000
heap
page read and write
6F4A000
direct allocation
page read and write
7912000
direct allocation
page read and write
28A0000
heap
page read and write
7A1A000
direct allocation
page read and write
6D78000
direct allocation
page read and write
50FA000
heap
page read and write
3DEE000
direct allocation
page read and write
56F2000
direct allocation
page read and write
58B9000
heap
page read and write
510A000
heap
page read and write
695A000
direct allocation
page read and write
5597000
heap
page read and write
32FC000
heap
page read and write
5170000
heap
page read and write
7182000
direct allocation
page read and write
4D53000
heap
page read and write
4B15000
heap
page read and write
4D71000
heap
page read and write
4B07000
heap
page read and write
32D3000
heap
page read and write
3EA8000
direct allocation
page read and write
6FDA000
direct allocation
page read and write
289E000
heap
page read and write
3E68000
direct allocation
page read and write
6DEA000
direct allocation
page read and write
4ACB000
heap
page read and write
716E000
direct allocation
page read and write
74E2000
direct allocation
page read and write
9F0000
direct allocation
page read and write
4D90000
heap
page read and write
28A2000
heap
page read and write
7046000
direct allocation
page read and write
7B6C000
direct allocation
page read and write
5641000
heap
page read and write
2D58000
direct allocation
page read and write
446C000
direct allocation
page read and write
3F62000
direct allocation
page read and write
4166000
direct allocation
page read and write
51BC000
heap
page read and write
707E000
direct allocation
page read and write
309A000
direct allocation
page read and write
7700000
direct allocation
page read and write
2A7A000
heap
page read and write
2A95000
heap
page read and write
58A2000
heap
page read and write
50EA000
heap
page read and write
76CE000
direct allocation
page read and write
510A000
heap
page read and write
58F4000
heap
page read and write
28A8000
heap
page read and write
532D000
heap
page read and write
4172000
direct allocation
page read and write
6C34000
direct allocation
page read and write
2F7D000
stack
page read and write
5BF7000
heap
page read and write
58C9000
heap
page read and write
7012000
direct allocation
page read and write
43C8000
direct allocation
page read and write
3E5E000
direct allocation
page read and write
31EC000
direct allocation
page read and write
300C000
direct allocation
page read and write
53D7000
heap
page read and write
2B2C000
direct allocation
page read and write
2A75000
heap
page read and write
2974000
direct allocation
page read and write
50DB000
heap
page read and write
3B98000
direct allocation
page read and write
58D8000
heap
page read and write
4624000
direct allocation
page read and write
58C9000
heap
page read and write
58EC000
heap
page read and write
573C000
heap
page read and write
510E000
heap
page read and write
2C2E000
direct allocation
page read and write
30C7000
heap
page read and write
76CE000
direct allocation
page read and write
444E000
stack
page read and write
52D9000
heap
page read and write
4CE0000
trusted library allocation
page read and write
56E2000
direct allocation
page read and write
4AA7000
heap
page read and write
54CA000
heap
page read and write
1C49000
unkown
page read and write
50DB000
heap
page read and write
2A7A000
heap
page read and write
7B2E000
direct allocation
page read and write
7C0C000
direct allocation
page read and write
2CB0000
direct allocation
page read and write
5304000
heap
page read and write
31BC000
direct allocation
page read and write
4B5D000
heap
page read and write
73C0000
direct allocation
page read and write
4680000
direct allocation
page read and write
74AA000
direct allocation
page read and write
2CFC000
direct allocation
page read and write
7148000
direct allocation
page read and write
4D87000
heap
page read and write
7C06000
direct allocation
page read and write
6F5E000
direct allocation
page read and write
4D1F000
heap
page read and write
4B48000
heap
page read and write
2892000
heap
page read and write
28A2000
heap
page read and write
2897000
heap
page read and write
4D29000
heap
page read and write
4D2E000
heap
page read and write
58E8000
heap
page read and write
7E76000
direct allocation
page read and write
678C000
direct allocation
page read and write
7CCE000
direct allocation
page read and write
296C000
direct allocation
page read and write
450C000
direct allocation
page read and write
2807000
heap
page read and write
6D80000
direct allocation
page read and write
58EC000
heap
page read and write
32DE000
heap
page read and write
6CE4000
direct allocation
page read and write
43B6000
direct allocation
page read and write
516B000
heap
page read and write
5304000
heap
page read and write
2A70000
heap
page read and write
6BEA000
direct allocation
page read and write
4D4A000
heap
page read and write
730A000
direct allocation
page read and write
4D74000
heap
page read and write
529D000
heap
page read and write
421C000
direct allocation
page read and write
6E78000
direct allocation
page read and write
4D27000
heap
page read and write
56AE000
direct allocation
page read and write
52BE000
stack
page read and write
5BE2000
direct allocation
page read and write
28BD000
heap
page read and write
4D11000
heap
page read and write
2FBA000
direct allocation
page read and write
4AE0000
heap
page read and write
510A000
heap
page read and write
2A64000
heap
page read and write
58DD000
heap
page read and write
35AA000
direct allocation
page read and write
5BE6000
heap
page read and write
3006000
direct allocation
page read and write
4D53000
heap
page read and write
32D3000
heap
page read and write
24C60000
direct allocation
page read and write
2FF0000
direct allocation
page read and write
4D3F000
heap
page read and write
58E8000
heap
page read and write
29A6000
direct allocation
page read and write
5338000
heap
page read and write
510A000
heap
page read and write
3574000
direct allocation
page read and write
462C000
direct allocation
page read and write
3080000
direct allocation
page execute and read and write
5954000
heap
page read and write
5116000
heap
page read and write
5C0B000
direct allocation
page read and write
3E0C000
direct allocation
page read and write
282F000
stack
page read and write
8D0000
unkown
page readonly
28A5000
heap
page read and write
532D000
heap
page read and write
3C1A000
direct allocation
page read and write
58F4000
heap
page read and write
76AA000
direct allocation
page read and write
7BDC000
direct allocation
page read and write
764E000
direct allocation
page read and write
75DA000
direct allocation
page read and write
4339000
direct allocation
page read and write
3070000
direct allocation
page read and write
7822000
direct allocation
page read and write
28B5000
heap
page read and write
50EA000
heap
page read and write
58D8000
heap
page read and write
6802000
direct allocation
page read and write
3DC0000
direct allocation
page read and write
6EC6000
direct allocation
page read and write
58D8000
heap
page read and write
3054000
direct allocation
page read and write
535C000
heap
page read and write
510A000
heap
page read and write
7AB2000
direct allocation
page read and write
50FA000
heap
page read and write
4CE0000
trusted library allocation
page read and write
2892000
heap
page read and write
7094000
direct allocation
page read and write
370C000
direct allocation
page read and write
58C9000
heap
page read and write
4A7C000
heap
page read and write
4AB1000
heap
page read and write
47E1000
direct allocation
page read and write
3C9E000
direct allocation
page read and write
58C8000
heap
page read and write
3A18000
direct allocation
page read and write
3B78000
direct allocation
page read and write
63DA000
heap
page read and write
5A0A000
heap
page read and write
4AA7000
heap
page read and write
4378000
direct allocation
page read and write
683C000
direct allocation
page read and write
202D000
unkown
page readonly
50FF000
heap
page read and write
58C8000
heap
page read and write
4A1E000
stack
page read and write
2CEE000
direct allocation
page read and write
58A4000
heap
page read and write
43CC000
direct allocation
page read and write
30C2000
direct allocation
page read and write
2FDC000
direct allocation
page read and write
532C000
heap
page read and write
544D000
heap
page read and write
4D63000
heap
page read and write
2530000
heap
page read and write
755E000
direct allocation
page read and write
281A000
direct allocation
page read and write
532F000
heap
page read and write
4AC6000
heap
page read and write
52BB000
heap
page read and write
32DB000
heap
page read and write
4AF6000
heap
page read and write
4CF1000
heap
page read and write
6E34000
direct allocation
page read and write
5921000
heap
page read and write
2C2B000
direct allocation
page read and write
72F0000
direct allocation
page read and write
4D11000
heap
page read and write
57F3000
heap
page read and write
6AE6000
direct allocation
page read and write
7BEA000
direct allocation
page read and write
4A6D000
heap
page read and write
7684000
direct allocation
page read and write
58EC000
heap
page read and write
6F78000
direct allocation
page read and write
2A7B000
heap
page read and write
5550000
trusted library allocation
page read and write
72F8000
direct allocation
page read and write
288A000
heap
page read and write
CC1000
unkown
page execute read
7050000
direct allocation
page read and write
5A7C000
heap
page read and write
73E6000
direct allocation
page read and write
27FF000
heap
page read and write
69DA000
direct allocation
page read and write
480B000
direct allocation
page read and write
5539000
heap
page read and write
2D6A000
direct allocation
page read and write
3D9C000
direct allocation
page read and write
5CA4000
direct allocation
page read and write
4B43000
heap
page read and write
4A7B000
heap
page read and write
4D27000
heap
page read and write
2DF0000
direct allocation
page read and write
4D4A000
heap
page read and write
58EC000
heap
page read and write
2EB8000
direct allocation
page read and write
4A6D000
heap
page read and write
7C54000
direct allocation
page read and write
53B0000
heap
page read and write
28B9000
direct allocation
page read and write
7DBC000
direct allocation
page read and write
4250000
direct allocation
page read and write
4B13000
heap
page read and write
7C22000
direct allocation
page read and write
778E000
direct allocation
page read and write
4648000
direct allocation
page read and write
83D000
stack
page read and write
43D8000
direct allocation
page read and write
6768000
direct allocation
page read and write
2F6E000
direct allocation
page read and write
7AE4000
direct allocation
page read and write
4D53000
heap
page read and write
74D0000
direct allocation
page read and write
58C8000
heap
page read and write
4AE0000
heap
page read and write
2EA8000
direct allocation
page read and write
726A000
direct allocation
page read and write
471B000
direct allocation
page read and write
537B000
heap
page read and write
50DB000
heap
page read and write
5817000
heap
page read and write
990000
heap
page read and write
3E70000
direct allocation
page read and write
4A7C000
heap
page read and write
32B4000
direct allocation
page read and write
4D64000
heap
page read and write
6BE0000
direct allocation
page read and write
704A000
direct allocation
page read and write
3B74000
direct allocation
page read and write
1293000
unkown
page read and write
4ACD000
heap
page read and write
4D22000
heap
page read and write
72AA000
direct allocation
page read and write
7BE2000
direct allocation
page read and write
58E8000
heap
page read and write
4AA7000
heap
page read and write
2C8C000
direct allocation
page read and write
22DFF000
stack
page read and write
2962000
direct allocation
page read and write
5C2C000
direct allocation
page read and write
58C9000
heap
page read and write
5B67000
heap
page read and write
2CB8000
direct allocation
page read and write
24D1B000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
50EA000
heap
page read and write
532C000
heap
page read and write
32DE000
heap
page read and write
7A64000
direct allocation
page read and write
2CFE000
direct allocation
page read and write
6C06000
direct allocation
page read and write
2896000
heap
page read and write
58E8000
heap
page read and write
7B26000
direct allocation
page read and write
6D06000
direct allocation
page read and write
2CB8000
direct allocation
page read and write
2880000
heap
page read and write
4A67000
heap
page read and write
7538000
direct allocation
page read and write
798A000
direct allocation
page read and write
7A8E000
direct allocation
page read and write
72D8000
direct allocation
page read and write
4ACF000
heap
page read and write
5626000
heap
page read and write
46CE000
direct allocation
page read and write
4AE5000
heap
page read and write
6A16000
direct allocation
page read and write
2DDA000
direct allocation
page read and write
58EC000
heap
page read and write
3A96000
direct allocation
page read and write
3ACC000
direct allocation
page read and write
2880000
heap
page read and write
7642000
direct allocation
page read and write
4D53000
heap
page read and write
5307000
heap
page read and write
7796000
direct allocation
page read and write
58E8000
heap
page read and write
7D8A000
direct allocation
page read and write
4CD4000
heap
page read and write
2BB8000
direct allocation
page read and write
772C000
direct allocation
page read and write
6D18000
direct allocation
page read and write
58E8000
heap
page read and write
7222000
direct allocation
page read and write
5739000
heap
page read and write
58E8000
heap
page read and write
7444000
direct allocation
page read and write
4D1A000
heap
page read and write
6E9E000
direct allocation
page read and write
7ABA000
direct allocation
page read and write
2C26000
direct allocation
page read and write
5CDA000
direct allocation
page read and write
56EF000
heap
page read and write
5CDD000
direct allocation
page read and write
2CF2000
direct allocation
page read and write
510E000
heap
page read and write
41C4000
direct allocation
page read and write
516B000
heap
page read and write
58C9000
heap
page read and write
2D3E000
direct allocation
page read and write
4D1A000
heap
page read and write
42F5000
direct allocation
page read and write
70EE000
direct allocation
page read and write
52CF000
heap
page read and write
58B4000
heap
page read and write
4D64000
heap
page read and write
2A76000
heap
page read and write
7526000
direct allocation
page read and write
47A2000
direct allocation
page read and write
32D5000
heap
page read and write
4AAE000
heap
page read and write
2790000
heap
page read and write
4EE0000
heap
page read and write
289A000
heap
page read and write
7DB7000
direct allocation
page read and write
58C8000
heap
page read and write
6F40000
direct allocation
page read and write
4D27000
heap
page read and write
4D1A000
heap
page read and write
4D80000
heap
page read and write
58D9000
heap
page read and write
58EB000
heap
page read and write
2AF0000
heap
page read and write
4ACD000
heap
page read and write
44E8000
direct allocation
page read and write
2807000
heap
page read and write
4D14000
heap
page read and write
510A000
heap
page read and write
58EC000
heap
page read and write
58C8000
heap
page read and write
384A000
direct allocation
page read and write
4B48000
heap
page read and write
2847000
direct allocation
page read and write
517D000
heap
page read and write
4D56000
heap
page read and write
4AC6000
heap
page read and write
50FB000
heap
page read and write
2C30000
direct allocation
page read and write
5BC7000
heap
page read and write
2892000
heap
page read and write
2A6C000
heap
page read and write
2DA6000
direct allocation
page read and write
2C60000
direct allocation
page read and write
723E000
direct allocation
page read and write
5312000
heap
page read and write
4ADD000
heap
page read and write
4D1A000
heap
page read and write
6C7C000
direct allocation
page read and write
2DAC000
direct allocation
page read and write
28D0000
direct allocation
page read and write
7580000
direct allocation
page read and write
47D1000
direct allocation
page read and write
4D27000
heap
page read and write
4D2E000
heap
page read and write
2950000
direct allocation
page read and write
4D53000
heap
page read and write
4D4A000
heap
page read and write
4F60000
trusted library allocation
page read and write
7090000
direct allocation
page read and write
71F6000
direct allocation
page read and write
4AA7000
heap
page read and write
53D7000
heap
page read and write
6EDE000
direct allocation
page read and write
289B000
heap
page read and write
510A000
heap
page read and write
4D13000
heap
page read and write
4A6B000
heap
page read and write
58EC000
heap
page read and write
38C4000
direct allocation
page read and write
3946000
direct allocation
page read and write
6BF2000
direct allocation
page read and write
32FC000
heap
page read and write
58B9000
heap
page read and write
50DB000
heap
page read and write
72D4000
direct allocation
page read and write
4D63000
heap
page read and write
112E000
unkown
page execute read
4D49000
heap
page read and write
2D0C000
direct allocation
page read and write
4A64000
heap
page read and write
32D8000
heap
page read and write
58F4000
heap
page read and write
3E5A000
direct allocation
page read and write
6BA8000
direct allocation
page read and write
5539000
heap
page read and write
52FD000
heap
page read and write
7810000
direct allocation
page read and write
50EA000
heap
page read and write
365C000
direct allocation
page read and write
5BE5000
direct allocation
page read and write
532C000
heap
page read and write
6B84000
direct allocation
page read and write
4749000
direct allocation
page read and write
531C000
heap
page read and write
58C8000
heap
page read and write
2C6A000
direct allocation
page read and write
4142000
direct allocation
page read and write
5317000
heap
page read and write
32FE000
direct allocation
page read and write
7940000
direct allocation
page read and write
4D98000
heap
page read and write
6C6C000
direct allocation
page read and write
441E000
direct allocation
page read and write
67B0000
direct allocation
page read and write
6F7A000
direct allocation
page read and write
2A7D000
stack
page read and write
6DBA000
direct allocation
page read and write
56BE000
direct allocation
page read and write
52C0000
heap
page read and write
58E8000
heap
page read and write
7200000
direct allocation
page read and write
4AB0000
heap
page read and write
4292000
direct allocation
page read and write
4A7B000
heap
page read and write
6BBA000
direct allocation
page read and write
2C9C000
direct allocation
page read and write
69C6000
direct allocation
page read and write
28A5000
heap
page read and write
4AAD000
heap
page read and write
4D4A000
heap
page read and write
787C000
direct allocation
page read and write
42DA000
direct allocation
page read and write
47F9000
direct allocation
page read and write
2892000
heap
page read and write
766C000
direct allocation
page read and write
510A000
heap
page read and write
4858000
direct allocation
page read and write
58EC000
heap
page read and write
4AE0000
heap
page read and write
58C8000
heap
page read and write
6D3A000
direct allocation
page read and write
58D8000
heap
page read and write
32E0000
heap
page read and write
2A9A000
heap
page read and write
56EE000
heap
page read and write
58B9000
heap
page read and write
2ECE000
direct allocation
page read and write
3CB0000
direct allocation
page read and write
58D8000
heap
page read and write
2F94000
direct allocation
page read and write
4D27000
heap
page read and write
2F86000
direct allocation
page read and write
6C5A000
direct allocation
page read and write
6F02000
direct allocation
page read and write
2816000
direct allocation
page read and write
28AE000
heap
page read and write
36E0000
direct allocation
page read and write
58F4000
heap
page read and write
4B45000
heap
page read and write
2A83000
heap
page read and write
52DE000
heap
page read and write
354E000
direct allocation
page read and write
410A000
direct allocation
page read and write
4800000
direct allocation
page read and write
58D8000
heap
page read and write
5116000
heap
page read and write
4D63000
heap
page read and write
2BFE000
stack
page read and write
529C000
heap
page read and write
4D1E000
heap
page read and write
58F4000
heap
page read and write
5313000
heap
page read and write
4AE1000
heap
page read and write
4A82000
heap
page read and write
397E000
direct allocation
page read and write
4D4A000
heap
page read and write
2BED000
stack
page read and write
4D1F000
heap
page read and write
3668000
direct allocation
page read and write
2E30000
direct allocation
page read and write
50DB000
heap
page read and write
739A000
direct allocation
page read and write
4811000
direct allocation
page read and write
6BA3000
direct allocation
page read and write
4D85000
heap
page read and write
252CC000
direct allocation
page read and write
58D8000
heap
page read and write
52C4000
heap
page read and write
78B1000
direct allocation
page read and write
7CB4000
direct allocation
page read and write
7A58000
direct allocation
page read and write
314E000
direct allocation
page read and write
587B000
heap
page read and write
68B8000
direct allocation
page read and write
7102000
direct allocation
page read and write
28BC000
heap
page read and write
39EC000
direct allocation
page read and write
58B9000
heap
page read and write
5324000
heap
page read and write
2A92000
heap
page read and write
55B4000
heap
page read and write
4D53000
heap
page read and write
7274000
direct allocation
page read and write
7A64000
direct allocation
page read and write
4A7B000
heap
page read and write
58C9000
heap
page read and write
47AA000
direct allocation
page read and write
50FA000
heap
page read and write
74BC000
direct allocation
page read and write
4D13000
heap
page read and write
5313000
heap
page read and write
2874000
heap
page read and write
2F8B000
stack
page read and write
2A88000
heap
page read and write
7BA2000
direct allocation
page read and write
2E1A000
direct allocation
page read and write
29D3000
heap
page read and write
28AE000
direct allocation
page read and write
509D000
heap
page read and write
6B86000
direct allocation
page read and write
6EC9000
direct allocation
page read and write
6F26000
direct allocation
page read and write
6840000
direct allocation
page read and write
71D2000
direct allocation
page read and write
2970000
direct allocation
page read and write
4D27000
heap
page read and write
4A67000
heap
page read and write
6A50000
direct allocation
page read and write
4D27000
heap
page read and write
4D7B000
heap
page read and write
58F4000
heap
page read and write
7520000
direct allocation
page read and write
32DD000
heap
page read and write
58E5000
heap
page read and write
72FA000
direct allocation
page read and write
58C9000
heap
page read and write
5116000
heap
page read and write
4D70000
heap
page read and write
5724000
heap
page read and write
2BE0000
heap
page read and write
6D74000
direct allocation
page read and write
4D3F000
heap
page read and write
5A15000
heap
page read and write
3C8E000
direct allocation
page read and write
24FDD000
stack
page read and write
5315000
heap
page read and write
447A000
direct allocation
page read and write
7684000
direct allocation
page read and write
52D9000
heap
page read and write
53A7000
heap
page read and write
4A7C000
heap
page read and write
2886000
direct allocation
page read and write
78C8000
direct allocation
page read and write
32F2000
heap
page read and write
4CD4000
heap
page read and write
363E000
direct allocation
page read and write
2A66000
heap
page read and write
50EA000
heap
page read and write
28AE000
heap
page read and write
4D7C000
heap
page read and write
7892000
direct allocation
page read and write
6A46000
direct allocation
page read and write
7AC4000
direct allocation
page read and write
32E5000
heap
page read and write
393A000
direct allocation
page read and write
2A61000
heap
page read and write
52DF000
heap
page read and write
4D53000
heap
page read and write
4D53000
heap
page read and write
4D11000
heap
page read and write
46DC000
direct allocation
page read and write
2B24000
direct allocation
page read and write
58D8000
heap
page read and write
5D1D000
direct allocation
page read and write
507D000
heap
page read and write
58B9000
heap
page read and write
4AAE000
heap
page read and write
4718000
direct allocation
page read and write
510E000
heap
page read and write
7C80000
direct allocation
page read and write
2FB0000
direct allocation
page read and write
4D1D000
heap
page read and write
58F4000
heap
page read and write
43B9000
direct allocation
page read and write
503B000
heap
page read and write
4D3F000
heap
page read and write
474C000
direct allocation
page read and write
58C8000
heap
page read and write
3913000
direct allocation
page read and write
480E000
direct allocation
page read and write
517B000
heap
page read and write
7BFC000
direct allocation
page read and write
4FFC000
heap
page read and write
2039000
unkown
page read and write
4312000
direct allocation
page read and write
32F2000
heap
page read and write
3650000
direct allocation
page read and write
50FA000
heap
page read and write
58E8000
heap
page read and write
4CE0000
trusted library allocation
page read and write
7476000
direct allocation
page read and write
4ACD000
heap
page read and write
575E000
direct allocation
page read and write
323A000
direct allocation
page read and write
790C000
direct allocation
page read and write
4AA7000
heap
page read and write
2D14000
direct allocation
page read and write
4D3F000
heap
page read and write
76F6000
direct allocation
page read and write
2D80000
direct allocation
page read and write
6EA6000
direct allocation
page read and write
6C26000
direct allocation
page read and write
58C8000
heap
page read and write
2C06000
direct allocation
page read and write
2B8C000
direct allocation
page read and write
4DA3000
heap
page read and write
2C7E000
direct allocation
page read and write
532C000
heap
page read and write
3254000
heap
page read and write
288A000
heap
page read and write
7612000
direct allocation
page read and write
755E000
direct allocation
page read and write
73AE000
direct allocation
page read and write
58D8000
heap
page read and write
58E6000
heap
page read and write
58D8000
heap
page read and write
52DA000
heap
page read and write
3C2C000
direct allocation
page read and write
3570000
direct allocation
page read and write
46FF000
direct allocation
page read and write
56A0000
heap
page read and write
288A000
heap
page read and write
77DA000
direct allocation
page read and write
47B6000
direct allocation
page read and write
7B40000
direct allocation
page read and write
4AC6000
heap
page read and write
4556000
direct allocation
page read and write
2B40000
direct allocation
page read and write
3C0C000
direct allocation
page read and write
38E0000
direct allocation
page read and write
72C6000
direct allocation
page read and write
4ACD000
heap
page read and write
50C7000
heap
page read and write
2E76000
direct allocation
page read and write
6DD6000
direct allocation
page read and write
6F64000
direct allocation
page read and write
2E84000
direct allocation
page read and write
4D2B000
heap
page read and write
5116000
heap
page read and write
4ACD000
heap
page read and write
283E000
direct allocation
page read and write
5305000
heap
page read and write
4D53000
heap
page read and write
58EC000
heap
page read and write
4D27000
heap
page read and write
4306000
direct allocation
page read and write
32DB000
heap
page read and write
33C2000
direct allocation
page read and write
7474000
direct allocation
page read and write
679E000
direct allocation
page read and write
5271000
heap
page read and write
7506000
direct allocation
page read and write
38AB000
direct allocation
page read and write
4ADC000
heap
page read and write
32B8000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
2EDC000
direct allocation
page read and write
4930000
direct allocation
page read and write
73E8000
direct allocation
page read and write
3200000
direct allocation
page read and write
4A6D000
heap
page read and write
2C08000
direct allocation
page read and write
3CC2000
direct allocation
page read and write
32BF000
heap
page read and write
2D24000
direct allocation
page read and write
3ECC000
direct allocation
page read and write
7926000
direct allocation
page read and write
73F4000
direct allocation
page read and write
2FA8000
direct allocation
page read and write
2A61000
heap
page read and write
49DE000
stack
page read and write
303E000
direct allocation
page read and write
6CD8000
direct allocation
page read and write
289B000
heap
page read and write
58D8000
heap
page read and write
36DC000
direct allocation
page read and write
5305000
heap
page read and write
409E000
direct allocation
page read and write
6BAC000
direct allocation
page read and write
3A82000
direct allocation
page read and write
41BC000
direct allocation
page read and write
52DC000
heap
page read and write
3C52000
direct allocation
page read and write
2DA0000
direct allocation
page read and write
7126000
direct allocation
page read and write
2892000
heap
page read and write
28B7000
heap
page read and write
4AF8000
heap
page read and write
28A6000
heap
page read and write
58F4000
heap
page read and write
3118000
direct allocation
page read and write
5092000
heap
page read and write
5A53000
heap
page read and write
4D39000
heap
page read and write
29CE000
direct allocation
page read and write
4CE5000
heap
page read and write
4CE4000
heap
page read and write
706E000
direct allocation
page read and write
3706000
direct allocation
page read and write
2FFA000
direct allocation
page read and write
2E62000
direct allocation
page read and write
50DB000
heap
page read and write
2C1C000
direct allocation
page read and write
2E59000
direct allocation
page read and write
5371000
heap
page read and write
32E1000
heap
page read and write
32F4000
heap
page read and write
2B97000
direct allocation
page read and write
32FC000
heap
page read and write
3822000
direct allocation
page read and write
7666000
direct allocation
page read and write
1DC0000
heap
page read and write
4B3E000
heap
page read and write
6D4C000
direct allocation
page read and write
4D53000
heap
page read and write
7C6C000
direct allocation
page read and write
510A000
heap
page read and write
5860000
heap
page read and write
6A80000
direct allocation
page read and write
6C26000
direct allocation
page read and write
6F20000
direct allocation
page read and write
5C37000
heap
page read and write
5332000
heap
page read and write
5100000
heap
page read and write
4D26000
heap
page read and write
7C2C000
direct allocation
page read and write
78E8000
direct allocation
page read and write
714C000
direct allocation
page read and write
3D0C000
direct allocation
page read and write
532C000
heap
page read and write
28A5000
heap
page read and write
6950000
direct allocation
page read and write
41B0000
direct allocation
page read and write
4D42000
heap
page read and write
58F4000
heap
page read and write
586E000
heap
page read and write
6E6E000
direct allocation
page read and write
32F2000
heap
page read and write
77A2000
direct allocation
page read and write
317E000
direct allocation
page read and write
4490000
heap
page read and write
2520000
direct allocation
page read and write
5507000
heap
page read and write
7990000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
54A1000
heap
page read and write
288B000
heap
page read and write
6F80000
direct allocation
page read and write
6900000
direct allocation
page read and write
4ACC000
heap
page read and write
4184000
direct allocation
page read and write
6B2A000
direct allocation
page read and write
469C000
direct allocation
page read and write
2879000
heap
page read and write
50EA000
heap
page read and write
32FC000
heap
page read and write
5709000
heap
page read and write
58C8000
heap
page read and write
2FA4000
direct allocation
page read and write
73C0000
direct allocation
page read and write
2886000
heap
page read and write
436A000
direct allocation
page read and write
32D2000
heap
page read and write
53BB000
heap
page read and write
2FC2000
direct allocation
page read and write
2892000
heap
page read and write
4496000
heap
page read and write
252A0000
direct allocation
page read and write
2A95000
heap
page read and write
6B46000
direct allocation
page read and write
4AD0000
heap
page read and write
6D70000
direct allocation
page read and write
58E8000
heap
page read and write
4D0D000
heap
page read and write
4CE4000
heap
page read and write
75E6000
direct allocation
page read and write
47BF000
direct allocation
page read and write
32C1000
heap
page read and write
4D27000
heap
page read and write
5BDE000
direct allocation
page read and write
371E000
direct allocation
page read and write
48BD000
stack
page read and write
3D6A000
direct allocation
page read and write
43D0000
direct allocation
page read and write
4714000
direct allocation
page read and write
4740000
direct allocation
page read and write
4AF7000
heap
page read and write
2083000
unkown
page read and write
28A2000
heap
page read and write
6A1C000
direct allocation
page read and write
58D9000
heap
page read and write
7630000
direct allocation
page read and write
423C000
direct allocation
page read and write
3AD0000
direct allocation
page read and write
7544000
direct allocation
page read and write
3547000
direct allocation
page read and write
2B66000
direct allocation
page read and write
6B8E000
direct allocation
page read and write
58EC000
heap
page read and write
784A000
direct allocation
page read and write
78C8000
direct allocation
page read and write
24A1F000
stack
page read and write
4CE9000
heap
page read and write
731E000
direct allocation
page read and write
6980000
direct allocation
page read and write
2A70000
heap
page read and write
47CE000
direct allocation
page read and write
4D20000
heap
page read and write
54A7000
heap
page read and write
37A8000
direct allocation
page read and write
5A78000
heap
page read and write
2B3E000
direct allocation
page read and write
77BA000
direct allocation
page read and write
72E6000
direct allocation
page read and write
6FA6000
direct allocation
page read and write
532D000
heap
page read and write
5463000
heap
page read and write
2A61000
heap
page read and write
288A000
heap
page read and write
4AC0000
heap
page read and write
289E000
heap
page read and write
2C72000
direct allocation
page read and write
2892000
heap
page read and write
4AF7000
heap
page read and write
4D53000
heap
page read and write
5813000
heap
page read and write
7A0E000
direct allocation
page read and write
3B8A000
direct allocation
page read and write
4A6B000
heap
page read and write
510A000
heap
page read and write
78BA000
direct allocation
page read and write
7CA2000
direct allocation
page read and write
3B2A000
direct allocation
page read and write
6F2E000
direct allocation
page read and write
37C4000
direct allocation
page read and write
401C000
direct allocation
page read and write
5305000
heap
page read and write
B60000
direct allocation
page read and write
50FA000
heap
page read and write
230B000
stack
page read and write
9A0000
heap
page read and write
4D27000
heap
page read and write
6D6C000
direct allocation
page read and write
4D63000
heap
page read and write
4D14000
heap
page read and write
3B64000
direct allocation
page read and write
31A2000
direct allocation
page read and write
5586000
heap
page read and write
7ED0000
direct allocation
page read and write
5004000
heap
page read and write
5827000
heap
page read and write
2998000
direct allocation
page read and write
4D53000
heap
page read and write
7A92000
direct allocation
page read and write
4AEB000
heap
page read and write
2A95000
heap
page read and write
4A6D000
heap
page read and write
4D4A000
heap
page read and write
77D0000
direct allocation
page read and write
281D000
heap
page read and write
58C9000
heap
page read and write
7800000
direct allocation
page read and write
3BAE000
direct allocation
page read and write
28BA000
heap
page read and write
3602000
direct allocation
page read and write
7A0000
heap
page read and write
46A6000
direct allocation
page read and write
3AF2000
direct allocation
page read and write
6878000
direct allocation
page read and write
4B23000
heap
page read and write
58E8000
heap
page read and write
41E0000
direct allocation
page read and write
75FA000
direct allocation
page read and write
7788000
direct allocation
page read and write
4D3F000
heap
page read and write
32F7000
heap
page read and write
4DCE000
heap
page read and write
22DFF000
stack
page read and write
4078000
direct allocation
page read and write
71B8000
direct allocation
page read and write
594E000
heap
page read and write
2893000
heap
page read and write
58EC000
heap
page read and write
2920000
direct allocation
page read and write
2E1E000
direct allocation
page read and write
42DE000
direct allocation
page read and write
568C000
heap
page read and write
2039000
unkown
page read and write
5321000
heap
page read and write
4405000
direct allocation
page read and write
4AC6000
heap
page read and write
32D7000
heap
page read and write
37E4000
direct allocation
page read and write
43FA000
direct allocation
page read and write
58EC000
heap
page read and write
4F60000
trusted library allocation
page read and write
4D44000
heap
page read and write
5304000
heap
page read and write
5080000
heap
page read and write
6C5A000
direct allocation
page read and write
7C34000
direct allocation
page read and write
3038000
direct allocation
page read and write
2E92000
direct allocation
page read and write
4D27000
heap
page read and write
2E80000
direct allocation
page read and write
4D53000
heap
page read and write
32FC000
heap
page read and write
76AE000
direct allocation
page read and write
28AE000
heap
page read and write
43D4000
direct allocation
page read and write
28BD000
heap
page read and write
50EA000
heap
page read and write
2874000
heap
page read and write
2C16000
direct allocation
page read and write
7A7C000
direct allocation
page read and write
530E000
heap
page read and write
4AE0000
heap
page read and write
6B5A000
direct allocation
page read and write
79FE000
direct allocation
page read and write
25260000
direct allocation
page read and write
2960000
heap
page read and write
4D1F000
heap
page read and write
23DD000
stack
page read and write
46F0000
direct allocation
page read and write
52DB000
heap
page read and write
53A6000
heap
page read and write
5653000
heap
page read and write
4D26000
heap
page read and write
5304000
heap
page read and write
3250000
direct allocation
page read and write
5308000
heap
page read and write
4AAF000
heap
page read and write
58B9000
heap
page read and write
4AE5000
heap
page read and write
3F2A000
direct allocation
page read and write
2BA2000
direct allocation
page read and write
4CF0000
remote allocation
page read and write
7E8B000
direct allocation
page read and write
5332000
heap
page read and write
7816000
direct allocation
page read and write
4D0D000
heap
page read and write
6E46000
direct allocation
page read and write
4D27000
heap
page read and write
54D6000
heap
page read and write
2892000
heap
page read and write
57E0000
heap
page read and write
4CF0000
remote allocation
page read and write
6D12000
direct allocation
page read and write
7378000
direct allocation
page read and write
1683000
unkown
page write copy
4D27000
heap
page read and write
76F2000
direct allocation
page read and write
253DF000
stack
page read and write
5304000
heap
page read and write
4D53000
heap
page read and write
483D000
stack
page read and write
7946000
direct allocation
page read and write
58EC000
heap
page read and write
4D54000
heap
page read and write
24FE000
stack
page read and write
6EAE000
direct allocation
page read and write
2A5F000
heap
page read and write
2CB4000
direct allocation
page read and write
7D10000
direct allocation
page read and write
7A35000
direct allocation
page read and write
76E6000
direct allocation
page read and write
2A75000
heap
page read and write
2ECE000
direct allocation
page read and write
788E000
direct allocation
page read and write
5728000
heap
page read and write
7B54000
direct allocation
page read and write
7CBC000
direct allocation
page read and write
73E4000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
6C00000
direct allocation
page read and write
2340000
heap
page read and write
7440000
direct allocation
page read and write
58EC000
heap
page read and write
4D53000
heap
page read and write
7656000
direct allocation
page read and write
4AC7000
heap
page read and write
4CD4000
heap
page read and write
7900000
direct allocation
page read and write
52DA000
heap
page read and write
31F4000
direct allocation
page read and write
6FD2000
direct allocation
page read and write
4AC6000
heap
page read and write
C4E000
stack
page read and write
3302000
direct allocation
page read and write
4AE0000
heap
page read and write
2A6A000
heap
page read and write
235FF000
stack
page read and write
7CB6000
direct allocation
page read and write
4A64000
heap
page read and write
4D27000
heap
page read and write
50EA000
heap
page read and write
4ACC000
heap
page read and write
786A000
direct allocation
page read and write
5314000
heap
page read and write
6E14000
direct allocation
page read and write
7D46000
direct allocation
page read and write
4D1D000
heap
page read and write
5343000
heap
page read and write
1683000
unkown
page read and write
32DA000
heap
page read and write
6C00000
direct allocation
page read and write
58F4000
heap
page read and write
77EC000
direct allocation
page read and write
7038000
direct allocation
page read and write
5C16000
heap
page read and write
4D27000
heap
page read and write
78EC000
direct allocation
page read and write
76DA000
direct allocation
page read and write
2C4C000
direct allocation
page read and write
2C88000
direct allocation
page read and write
4AA7000
heap
page read and write
28B5000
heap
page read and write
433C000
direct allocation
page read and write
4B07000
heap
page read and write
6DDA000
direct allocation
page read and write
2892000
heap
page read and write
2895000
heap
page read and write
9F8000
direct allocation
page read and write
2EB2000
direct allocation
page read and write
6E42000
direct allocation
page read and write
2A5F000
heap
page read and write
2893000
heap
page read and write
43F0000
direct allocation
page read and write
4D93000
heap
page read and write
711E000
direct allocation
page read and write
5CCE000
direct allocation
page read and write
71E2000
direct allocation
page read and write
4054000
direct allocation
page read and write
2076000
unkown
page read and write
50FA000
heap
page read and write
6F52000
direct allocation
page read and write
510A000
heap
page read and write
5171000
heap
page read and write
1D38000
direct allocation
page read and write
2CA6000
direct allocation
page read and write
4721000
direct allocation
page read and write
573D000
heap
page read and write
5CC1000
direct allocation
page read and write
4CD4000
heap
page read and write
79A3000
direct allocation
page read and write
532C000
heap
page read and write
4D1A000
heap
page read and write
7880000
direct allocation
page read and write
2A70000
heap
page read and write
3552000
direct allocation
page read and write
37BF000
direct allocation
page read and write
55EB000
heap
page read and write
2C12000
direct allocation
page read and write
5352000
heap
page read and write
5A19000
heap
page read and write
7648000
direct allocation
page read and write
58E8000
heap
page read and write
8D1000
unkown
page execute read
3E4A000
direct allocation
page read and write
5412000
heap
page read and write
4652000
direct allocation
page read and write
4AC1000
heap
page read and write
3AE4000
direct allocation
page read and write
517B000
heap
page read and write
58E8000
heap
page read and write
540B000
heap
page read and write
28B5000
heap
page read and write
28A5000
heap
page read and write
3D88000
direct allocation
page read and write
5D07000
direct allocation
page read and write
5352000
heap
page read and write
1C8A000
unkown
page read and write
5BDB000
direct allocation
page read and write
3F3E000
direct allocation
page read and write
6B4E000
direct allocation
page read and write
2D62000
direct allocation
page read and write
7EB6000
direct allocation
page read and write
4D26000
heap
page read and write
2EEA000
direct allocation
page read and write
6DA2000
direct allocation
page read and write
28AF000
heap
page read and write
6E5C000
direct allocation
page read and write
390E000
direct allocation
page read and write
5C68000
direct allocation
page read and write
58E8000
heap
page read and write
6F22000
direct allocation
page read and write
68DE000
direct allocation
page read and write
2880000
heap
page read and write
5270000
heap
page read and write
5C1A000
direct allocation
page read and write
2910000
heap
page read and write
58B9000
heap
page read and write
6938000
direct allocation
page read and write
4A72000
heap
page read and write
3BE2000
direct allocation
page read and write
53A7000
heap
page read and write
3EDE000
direct allocation
page read and write
3C7A000
direct allocation
page read and write
2898000
heap
page read and write
36A8000
direct allocation
page read and write
7B90000
direct allocation
page read and write
7DAE000
direct allocation
page read and write
28BE000
heap
page read and write
5314000
heap
page read and write
4D4A000
heap
page read and write
6E66000
direct allocation
page read and write
5B36000
heap
page read and write
28AE000
heap
page read and write
58B5000
heap
page read and write
280C000
direct allocation
page read and write
281D000
heap
page read and write
4D27000
heap
page read and write
4D10000
heap
page read and write
4D1A000
heap
page read and write
28B6000
heap
page read and write
6ECC000
direct allocation
page read and write
58D8000
heap
page read and write
56F8000
heap
page read and write
4D27000
heap
page read and write
77AA000
direct allocation
page read and write
58C9000
heap
page read and write
7DCC000
direct allocation
page read and write
289C000
heap
page read and write
3008000
direct allocation
page read and write
58E8000
heap
page read and write
739A000
direct allocation
page read and write
4470000
heap
page read and write
70C6000
direct allocation
page read and write
4A7C000
heap
page read and write
761E000
direct allocation
page read and write
6FA4000
direct allocation
page read and write
6AD6000
direct allocation
page read and write
2A71000
heap
page read and write
5813000
heap
page read and write
58E8000
heap
page read and write
286E000
heap
page read and write
3E18000
direct allocation
page read and write
6D34000
direct allocation
page read and write
581A000
heap
page read and write
58B9000
heap
page read and write
1808000
unkown
page read and write
2893000
heap
page read and write
387E000
direct allocation
page read and write
58F4000
heap
page read and write
1760000
unkown
page readonly
4D27000
heap
page read and write
C90000
heap
page read and write
4ACD000
heap
page read and write
36A2000
direct allocation
page read and write
308A000
direct allocation
page read and write
4688000
direct allocation
page read and write
6F44000
direct allocation
page read and write
4A66000
heap
page read and write
5116000
heap
page read and write
32C1000
heap
page read and write
7750000
direct allocation
page read and write
7CFA000
direct allocation
page read and write
4D4A000
heap
page read and write
2C84000
direct allocation
page read and write
58EC000
heap
page read and write
2FF5000
direct allocation
page read and write
2D6C000
direct allocation
page read and write
58E8000
heap
page read and write
4A9F000
heap
page read and write
75B4000
direct allocation
page read and write
304A000
direct allocation
page read and write
5586000
heap
page read and write
52DC000
heap
page read and write
7A66000
direct allocation
page read and write
7C60000
direct allocation
page read and write
4824000
direct allocation
page read and write
28BA000
heap
page read and write
4AB1000
heap
page read and write
3F06000
direct allocation
page read and write
7A64000
direct allocation
page read and write
2A83000
heap
page read and write
7A8E000
direct allocation
page read and write
7804000
direct allocation
page read and write
4CE0000
trusted library allocation
page read and write
3CA2000
direct allocation
page read and write
35EC000
direct allocation
page read and write
2813000
heap
page read and write
252D7000
direct allocation
page read and write
2A9C000
heap
page read and write
5337000
heap
page read and write
6EEB000
direct allocation
page read and write
3ABE000
direct allocation
page read and write
42C8000
direct allocation
page read and write
310C000
direct allocation
page read and write
7924000
direct allocation
page read and write
28A2000
heap
page read and write
3D6E000
direct allocation
page read and write
4AC6000
heap
page read and write
756E000
direct allocation
page read and write
4586000
direct allocation
page read and write
2FDE000
direct allocation
page read and write
2B56000
direct allocation
page read and write
4D21000
heap
page read and write
7DE6000
direct allocation
page read and write
5AB5000
heap
page read and write
3A62000
direct allocation
page read and write
3D10000
direct allocation
page read and write
2C08000
direct allocation
page read and write
510A000
heap
page read and write
6BB8000
direct allocation
page read and write
7E1A000
direct allocation
page read and write
2880000
heap
page read and write
4F60000
trusted library allocation
page read and write
32A2000
direct allocation
page read and write
52DC000
heap
page read and write
5330000
heap
page read and write
47E4000
direct allocation
page read and write
73E4000
direct allocation
page read and write
79D8000
direct allocation
page read and write
3788000
direct allocation
page read and write
3AA8000
direct allocation
page read and write
4D3F000
heap
page read and write
4D3F000
heap
page read and write
58A9000
heap
page read and write
2877000
heap
page read and write
58B9000
heap
page read and write
5315000
heap
page read and write
59D1000
heap
page read and write
2EAE000
direct allocation
page read and write
2C94000
direct allocation
page read and write
4B20000
heap
page read and write
4D53000
heap
page read and write
4D3F000
heap
page read and write
710C000
direct allocation
page read and write
594E000
heap
page read and write
32F3000
heap
page read and write
730C000
direct allocation
page read and write
2D5C000
direct allocation
page read and write
58B9000
heap
page read and write
2AF7000
heap
page read and write
5076000
heap
page read and write
35F2000
direct allocation
page read and write
5738000
direct allocation
page read and write
2874000
heap
page read and write
3CDA000
direct allocation
page read and write
6A76000
direct allocation
page read and write
4D7B000
heap
page read and write
46CA000
direct allocation
page read and write
2A61000
heap
page read and write
3C30000
direct allocation
page read and write
70E2000
direct allocation
page read and write
46C0000
direct allocation
page read and write
31A6000
direct allocation
page read and write
58C8000
heap
page read and write
52D8000
heap
page read and write
555B000
heap
page read and write
5305000
heap
page read and write
50EA000
heap
page read and write
6D30000
direct allocation
page read and write
7366000
direct allocation
page read and write
7DC0000
direct allocation
page read and write
46FA000
direct allocation
page read and write
42C8000
direct allocation
page read and write
29EA000
heap
page read and write
5116000
heap
page read and write
32F2000
heap
page read and write
32D2000
heap
page read and write
48FE000
stack
page read and write
2CB2000
direct allocation
page read and write
58B9000
heap
page read and write
53A4000
heap
page read and write
71EA000
direct allocation
page read and write
71C8000
direct allocation
page read and write
6DA6000
direct allocation
page read and write
5116000
heap
page read and write
7A1A000
direct allocation
page read and write
58F4000
heap
page read and write
1A50000
unkown
page readonly
46AE000
direct allocation
page read and write
594C000
heap
page read and write
737A000
direct allocation
page read and write
4A6D000
heap
page read and write
39BC000
direct allocation
page read and write
46D2000
direct allocation
page read and write
7000000
direct allocation
page read and write
4D53000
heap
page read and write
743B000
direct allocation
page read and write
4D6B000
heap
page read and write
6E8A000
direct allocation
page read and write
4AA7000
heap
page read and write
167C000
unkown
page read and write
50DB000
heap
page read and write
4AC1000
heap
page read and write
4D2B000
heap
page read and write
188F000
unkown
page readonly
4C50000
heap
page read and write
7A46000
direct allocation
page read and write
2AA7000
heap
page read and write
58E8000
heap
page read and write
2A66000
heap
page read and write
4598000
direct allocation
page read and write
50EA000
heap
page read and write
7488000
direct allocation
page read and write
7406000
direct allocation
page read and write
3698000
direct allocation
page read and write
28A6000
heap
page read and write
6CB4000
direct allocation
page read and write
231FF000
stack
page read and write
449E000
direct allocation
page read and write
2893000
heap
page read and write
7014000
direct allocation
page read and write
58E8000
heap
page read and write
4D83000
heap
page read and write
510A000
heap
page read and write
7D0C000
direct allocation
page read and write
50EA000
heap
page read and write
58D8000
heap
page read and write
50FA000
heap
page read and write
28AF000
heap
page read and write
3FF6000
direct allocation
page read and write
4DBD000
heap
page read and write
295E000
direct allocation
page read and write
6C54000
direct allocation
page read and write
32F2000
heap
page read and write
28B4000
heap
page read and write
494C000
direct allocation
page read and write
66EC000
direct allocation
page read and write
2BDC000
stack
page read and write
58D8000
heap
page read and write
58E8000
heap
page read and write
28B6000
heap
page read and write
4612000
direct allocation
page read and write
50FA000
heap
page read and write
6B96000
direct allocation
page read and write
58C9000
heap
page read and write
4D53000
heap
page read and write
6C22000
direct allocation
page read and write
74CE000
direct allocation
page read and write
4A81000
heap
page read and write
2893000
heap
page read and write
4D73000
heap
page read and write
5726000
direct allocation
page read and write
7E84000
direct allocation
page read and write
4D40000
heap
page read and write
4D53000
heap
page read and write
6AFC000
direct allocation
page read and write
480E000
direct allocation
page read and write
2E4A000
direct allocation
page read and write
24C5F000
stack
page read and write
7388000
direct allocation
page read and write
32D3000
heap
page read and write
58B9000
heap
page read and write
4B5D000
heap
page read and write
4568000
direct allocation
page read and write
181A000
unkown
page readonly
2A83000
heap
page read and write
30F0000
direct allocation
page read and write
29B0000
direct allocation
page read and write
4254000
direct allocation
page read and write
3108000
direct allocation
page read and write
7354000
direct allocation
page read and write
465C000
direct allocation
page read and write
6AC6000
direct allocation
page read and write
30B2000
direct allocation
page read and write
4AC7000
heap
page read and write
3DF8000
direct allocation
page read and write
7462000
direct allocation
page read and write
509B000
heap
page read and write
45C6000
direct allocation
page read and write
30C7000
heap
page read and write
41D6000
direct allocation
page read and write
4D15000
heap
page read and write
30E2000
direct allocation
page read and write
4D33000
heap
page read and write
7450000
direct allocation
page read and write
5116000
heap
page read and write
28AE000
heap
page read and write
6EC2000
direct allocation
page read and write
5313000
heap
page read and write
440D000
stack
page read and write
2CE4000
direct allocation
page read and write
5379000
heap
page read and write
28BE000
heap
page read and write
2EAC000
direct allocation
page read and write
72C2000
direct allocation
page read and write
1A65000
unkown
page readonly
3582000
direct allocation
page read and write
4CCF000
stack
page read and write
288A000
heap
page read and write
2874000
heap
page read and write
2B80000
direct allocation
page read and write
775A000
direct allocation
page read and write
7CB4000
direct allocation
page read and write
2E9E000
direct allocation
page read and write
4750000
remote allocation
page read and write
4D3F000
heap
page read and write
4812000
direct allocation
page read and write
5070000
heap
page read and write
5000000
heap
page read and write
5550000
trusted library allocation
page read and write
6884000
direct allocation
page read and write
510E000
heap
page read and write
5998000
heap
page read and write
47DA000
direct allocation
page read and write
6BAA000
direct allocation
page read and write
6CA6000
direct allocation
page read and write
58E8000
heap
page read and write
682E000
direct allocation
page read and write
3802000
direct allocation
page read and write
2BCF000
direct allocation
page read and write
4D4A000
heap
page read and write
50FA000
heap
page read and write
7498000
direct allocation
page read and write
7420000
direct allocation
page read and write
738A000
direct allocation
page read and write
586D000
heap
page read and write
2EF4000
direct allocation
page read and write
4D3F000
heap
page read and write
587A000
heap
page read and write
2874000
heap
page read and write
7CE0000
direct allocation
page read and write
7D54000
direct allocation
page read and write
4D60000
heap
page read and write
77A8000
direct allocation
page read and write
29F7000
heap
page read and write
4CF1000
heap
page read and write
2893000
heap
page read and write
5288000
heap
page read and write
6E52000
direct allocation
page read and write
6FFB000
direct allocation
page read and write
4D0D000
heap
page read and write
52D7000
heap
page read and write
73BC000
direct allocation
page read and write
6E36000
direct allocation
page read and write
4D53000
heap
page read and write
4D10000
heap
page read and write
4AC7000
heap
page read and write
5318000
heap
page read and write
6F32000
direct allocation
page read and write
739B000
direct allocation
page read and write
2917000
heap
page read and write
38BC000
direct allocation
page read and write
2EB0000
direct allocation
page read and write
6854000
direct allocation
page read and write
58E8000
heap
page read and write
6EF2000
direct allocation
page read and write
7210000
direct allocation
page read and write
4ADC000
heap
page read and write
440C000
direct allocation
page read and write
2C86000
direct allocation
page read and write
364A000
direct allocation
page read and write
773C000
direct allocation
page read and write
431D000
stack
page read and write
7082000
direct allocation
page read and write
58EC000
heap
page read and write
2FD8000
direct allocation
page read and write
4AC6000
heap
page read and write
6E78000
direct allocation
page read and write
6CB8000
direct allocation
page read and write
58B9000
heap
page read and write
52DA000
heap
page read and write
46BD000
direct allocation
page read and write
4BE0000
trusted library allocation
page read and write
7696000
direct allocation
page read and write
5A94000
heap
page read and write
3BD4000
direct allocation
page read and write
2E22000
direct allocation
page read and write
10FA000
unkown
page execute read
7776000
direct allocation
page read and write
5116000
heap
page read and write
3026000
direct allocation
page read and write
4D53000
heap
page read and write
4358000
direct allocation
page read and write
7AA6000
direct allocation
page read and write
2A70000
heap
page read and write
3074000
direct allocation
page read and write
54E8000
heap
page read and write
4A7C000
heap
page read and write
2A84000
heap
page read and write
6BCA000
direct allocation
page read and write
532D000
heap
page read and write
32FC000
heap
page read and write
4D54000
heap
page read and write
289C000
heap
page read and write
5470000
heap
page read and write
2A85000
heap
page read and write
251DF000
stack
page read and write
70EC000
direct allocation
page read and write
32D5000
heap
page read and write
58F4000
heap
page read and write
5371000
heap
page read and write
4CEC000
stack
page read and write
728E000
direct allocation
page read and write
78A2000
direct allocation
page read and write
323E000
direct allocation
page read and write
5CD4000
direct allocation
page read and write
506D000
heap
page read and write
78A6000
direct allocation
page read and write
7B0C000
direct allocation
page read and write
4783000
direct allocation
page read and write
4D3F000
heap
page read and write
7A40000
direct allocation
page read and write
2900000
remote allocation
page read and write
7DAA000
direct allocation
page read and write
7274000
direct allocation
page read and write
5728000
heap
page read and write
30BC000
direct allocation
page read and write
3B4E000
direct allocation
page read and write
28D6000
direct allocation
page read and write
2DB6000
direct allocation
page read and write
2DAE000
direct allocation
page read and write
4D2E000
heap
page read and write
72C6000
direct allocation
page read and write
2430000
heap
page read and write
4A7C000
heap
page read and write
4AAA000
heap
page read and write
4544000
direct allocation
page read and write
3776000
direct allocation
page read and write
28B5000
heap
page read and write
5304000
heap
page read and write
4AEB000
heap
page read and write
510E000
heap
page read and write
2874000
heap
page read and write
4A67000
heap
page read and write
71B4000
direct allocation
page read and write
6D5A000
direct allocation
page read and write
52CF000
heap
page read and write
53E8000
heap
page read and write
4AA7000
heap
page read and write
430F000
direct allocation
page read and write
2AA9000
heap
page read and write
2808000
direct allocation
page read and write
796C000
direct allocation
page read and write
4D14000
heap
page read and write
237FF000
stack
page read and write
4D53000
heap
page read and write
3128000
direct allocation
page read and write
32D6000
direct allocation
page read and write
2C36000
direct allocation
page read and write
1120000
unkown
page execute read
7B00000
direct allocation
page read and write
2E8A000
direct allocation
page read and write
6A3E000
direct allocation
page read and write
7BAC000
direct allocation
page read and write
58D8000
heap
page read and write
4D16000
heap
page read and write
58E8000
heap
page read and write
890000
heap
page read and write
2A7C000
heap
page read and write
7D00000
direct allocation
page read and write
4D9A000
heap
page read and write
7C18000
direct allocation
page read and write
479E000
direct allocation
page read and write
541A000
heap
page read and write
4D80000
heap
page read and write
4D53000
heap
page read and write
4D25000
heap
page read and write
288A000
heap
page read and write
7208000
direct allocation
page read and write
3062000
direct allocation
page read and write
2F2A000
direct allocation
page read and write
43A1000
direct allocation
page read and write
1683000
unkown
page read and write
5317000
heap
page read and write
4F60000
trusted library allocation
page read and write
4440000
direct allocation
page read and write
5318000
heap
page read and write
5379000
heap
page read and write
5641000
heap
page read and write
307C000
direct allocation
page read and write
2A64000
heap
page read and write
797E000
direct allocation
page read and write
4AE0000
heap
page read and write
32DB000
heap
page read and write
7E78000
direct allocation
page read and write
28BE000
heap
page read and write
493E000
direct allocation
page read and write
10EB000
unkown
page execute read
4AA7000
heap
page read and write
58DE000
heap
page read and write
5C3A000
direct allocation
page read and write
5116000
heap
page read and write
4D2F000
heap
page read and write
74E0000
direct allocation
page read and write
2C30000
direct allocation
page read and write
7EB4000
direct allocation
page read and write
321A000
direct allocation
page read and write
58F8000
heap
page read and write
5C0E000
direct allocation
page read and write
4D3F000
heap
page read and write
4D66000
heap
page read and write
438A000
direct allocation
page read and write
4D12000
heap
page read and write
43C2000
direct allocation
page read and write
4AA7000
heap
page read and write
58F4000
heap
page read and write
35A0000
direct allocation
page read and write
4AE0000
heap
page read and write
2A61000
heap
page read and write
7E8A000
direct allocation
page read and write
4A6B000
heap
page read and write
74AC000
direct allocation
page read and write
4D17000
heap
page read and write
3F72000
direct allocation
page read and write
72EA000
direct allocation
page read and write
4AE0000
heap
page read and write
53B2000
heap
page read and write
28A6000
heap
page read and write
31CA000
direct allocation
page read and write
233FF000
stack
page read and write
6C80000
direct allocation
page read and write
4D53000
heap
page read and write
4AC6000
heap
page read and write
B80000
heap
page read and write
7A52000
direct allocation
page read and write
7B4C000
direct allocation
page read and write
7408000
direct allocation
page read and write
5116000
heap
page read and write
6F68000
direct allocation
page read and write
4D4A000
heap
page read and write
538E000
heap
page read and write
282B000
direct allocation
page read and write
79C0000
direct allocation
page read and write
58B9000
heap
page read and write
6FC8000
direct allocation
page read and write
6A06000
direct allocation
page read and write
2F48000
direct allocation
page read and write
2C1C000
direct allocation
page read and write
5116000
heap
page read and write
532C000
heap
page read and write
36D0000
direct allocation
page read and write
7432000
direct allocation
page read and write
C85000
direct allocation
page read and write
5678000
heap
page read and write
2D56000
direct allocation
page read and write
A40000
heap
page read and write
6FDC000
direct allocation
page read and write
5304000
heap
page read and write
2910000
direct allocation
page read and write
4D11000
heap
page read and write
2C70000
direct allocation
page read and write
4CE3000
heap
page read and write
5340000
heap
page read and write
32D9000
heap
page read and write
58E8000
heap
page read and write
6C6E000
direct allocation
page read and write
4D27000
heap
page read and write
279D000
stack
page read and write
76EE000
direct allocation
page read and write
2EBA000
direct allocation
page read and write
784F000
direct allocation
page read and write
22FFF000
stack
page read and write
4D4A000
heap
page read and write
50EA000
heap
page read and write
4D53000
heap
page read and write
4AF3000
heap
page read and write
313A000
direct allocation
page read and write
77CC000
direct allocation
page read and write
2CEA000
direct allocation
page read and write
568E000
heap
page read and write
2C04000
direct allocation
page read and write
4D27000
heap
page read and write
7154000
direct allocation
page read and write
32F0000
heap
page read and write
7740000
direct allocation
page read and write
4AA7000
heap
page read and write
4A7B000
heap
page read and write
58C8000
heap
page read and write
52C0000
heap
page read and write
69D6000
direct allocation
page read and write
4D4A000
heap
page read and write
7038000
direct allocation
page read and write
7A4B000
direct allocation
page read and write
4D3F000
heap
page read and write
70A6000
direct allocation
page read and write
75F8000
direct allocation
page read and write
2C26000
direct allocation
page read and write
2EC6000
direct allocation
page read and write
251DD000
stack
page read and write
1614000
unkown
page execute read
555F000
heap
page read and write
52C5000
heap
page read and write
52FD000
heap
page read and write
499E000
stack
page read and write
2F08000
direct allocation
page read and write
5BA6000
heap
page read and write
1877000
unkown
page readonly
58F4000
heap
page read and write
32C1000
heap
page read and write
4ACD000
heap
page read and write
75EE000
direct allocation
page read and write
7600000
direct allocation
page read and write
7A58000
direct allocation
page read and write
29F7000
heap
page read and write
722C000
direct allocation
page read and write
6CA2000
direct allocation
page read and write
4CF2000
heap
page read and write
7504000
direct allocation
page read and write
5305000
heap
page read and write
3616000
direct allocation
page read and write
1DDF000
direct allocation
page read and write
6C7E000
direct allocation
page read and write
4408000
direct allocation
page read and write
28AE000
heap
page read and write
4D18000
heap
page read and write
28B0000
direct allocation
page read and write
58DB000
heap
page read and write
36F9000
direct allocation
page read and write
225F000
direct allocation
page read and write
76B4000
direct allocation
page read and write
4AE2000
heap
page read and write
47A7000
direct allocation
page read and write
705C000
direct allocation
page read and write
2C94000
direct allocation
page read and write
32F2000
heap
page read and write
2A8C000
heap
page read and write
6BE0000
direct allocation
page read and write
7580000
direct allocation
page read and write
58FA000
heap
page read and write
32F2000
heap
page read and write
2DCC000
direct allocation
page read and write
4A6C000
heap
page read and write
4D3F000
heap
page read and write
2C00000
direct allocation
page read and write
28AE000
heap
page read and write
2A6A000
heap
page read and write
32BD000
heap
page read and write
58D8000
heap
page read and write
2DC6000
direct allocation
page read and write
7D76000
direct allocation
page read and write
4D15000
heap
page read and write
4D1D000
heap
page read and write
77F4000
direct allocation
page read and write
7674000
direct allocation
page read and write
70B4000
direct allocation
page read and write
75C8000
direct allocation
page read and write
4A7B000
heap
page read and write
4F60000
trusted library allocation
page read and write
2EC2000
direct allocation
page read and write
760C000
direct allocation
page read and write
560B000
heap
page read and write
28A7000
heap
page read and write
681D000
direct allocation
page read and write
7E40000
direct allocation
page read and write
532D000
heap
page read and write
532E000
heap
page read and write
6D2A000
direct allocation
page read and write
275F000
stack
page read and write
7D06000
direct allocation
page read and write
28A9000
heap
page read and write
3B60000
direct allocation
page read and write
431B000
direct allocation
page read and write
2B94000
direct allocation
page read and write
2F9E000
direct allocation
page read and write
485C000
direct allocation
page read and write
510A000
heap
page read and write
28B6000
heap
page read and write
3960000
direct allocation
page read and write
32F2000
heap
page read and write
28BE000
heap
page read and write
5C32000
direct allocation
page read and write
7A20000
direct allocation
page read and write
2C2B000
direct allocation
page read and write
2880000
heap
page read and write
6C92000
direct allocation
page read and write
52CE000
heap
page read and write
3004000
direct allocation
page read and write
716B000
direct allocation
page read and write
6CDA000
direct allocation
page read and write
23BFF000
stack
page read and write
37FC000
direct allocation
page read and write
52E1000
heap
page read and write
2CAA000
direct allocation
page read and write
2D04000
direct allocation
page read and write
72A2000
direct allocation
page read and write
7C7C000
direct allocation
page read and write
128C000
unkown
page write copy
510A000
heap
page read and write
799E000
direct allocation
page read and write
795A000
direct allocation
page read and write
4D4A000
heap
page read and write
74EC000
direct allocation
page read and write
1D30000
direct allocation
page read and write
2BC000
stack
page read and write
50FA000
heap
page read and write
50EA000
heap
page read and write
4AB2000
heap
page read and write
3D20000
direct allocation
page read and write
4AFC000
heap
page read and write
4D29000
heap
page read and write
50EA000
heap
page read and write
2D60000
direct allocation
page read and write
6CEE000
direct allocation
page read and write
3D44000
direct allocation
page read and write
510E000
heap
page read and write
50DB000
heap
page read and write
2A93000
heap
page read and write
5A38000
heap
page read and write
71A4000
direct allocation
page read and write
50DB000
heap
page read and write
561D000
heap
page read and write
362C000
direct allocation
page read and write
4AAB000
heap
page read and write
5304000
heap
page read and write
7B1E000
direct allocation
page read and write
4AA7000
heap
page read and write
301A000
direct allocation
page read and write
50FA000
heap
page read and write
2C45000
direct allocation
page read and write
74AA000
direct allocation
page read and write
4D1D000
heap
page read and write
3FC0000
direct allocation
page read and write
510E000
heap
page read and write
5081000
heap
page read and write
487D000
stack
page read and write
517B000
heap
page read and write
3624000
direct allocation
page read and write
2FB8000
direct allocation
page read and write
513A000
heap
page read and write
2A61000
heap
page read and write
45BC000
direct allocation
page read and write
18C8000
unkown
page readonly
28B1000
heap
page read and write
4330000
direct allocation
page read and write
28A4000
direct allocation
page read and write
2A90000
heap
page read and write
50FB000
heap
page read and write
29BC000
direct allocation
page read and write
4D27000
heap
page read and write
4B4D000
heap
page read and write
4D25000
heap
page read and write
4D4A000
heap
page read and write
6E54000
direct allocation
page read and write
58A4000
heap
page read and write
581E000
heap
page read and write
5304000
heap
page read and write
4A81000
heap
page read and write
7A34000
direct allocation
page read and write
7E72000
direct allocation
page read and write
45A0000
direct allocation
page read and write
4AFC000
heap
page read and write
4D3F000
heap
page read and write
4F60000
trusted library allocation
page read and write
4D1E000
heap
page read and write
2AF5000
heap
page read and write
2A95000
heap
page read and write
4342000
direct allocation
page read and write
6E22000
direct allocation
page read and write
7C24000
direct allocation
page read and write
4ACC000
heap
page read and write
732E000
direct allocation
page read and write
2A9A000
heap
page read and write
560B000
heap
page read and write
6770000
direct allocation
page read and write
3190000
heap
page read and write
6B1A000
direct allocation
page read and write
5116000
heap
page read and write
58D8000
heap
page read and write
52E2000
heap
page read and write
252D9000
direct allocation
page read and write
79B4000
direct allocation
page read and write
6E96000
direct allocation
page read and write
4D3F000
heap
page read and write
2980000
direct allocation
page read and write
58D8000
heap
page read and write
58F4000
heap
page read and write
1896000
unkown
page readonly
2A70000
heap
page read and write
4D73000
heap
page read and write
73AE000
direct allocation
page read and write
167C000
unkown
page read and write
7474000
direct allocation
page read and write
4A7C000
heap
page read and write
4D53000
heap
page read and write
28BE000
heap
page read and write
C70000
direct allocation
page read and write
2A70000
heap
page read and write
58D8000
heap
page read and write
7354000
direct allocation
page read and write
58EC000
heap
page read and write
6DC8000
direct allocation
page read and write
4D3F000
heap
page read and write
3208000
heap
page read and write
5868000
heap
page read and write
32D2000
heap
page read and write
73D0000
direct allocation
page read and write
448A000
direct allocation
page read and write
4CD4000
heap
page read and write
68EE000
direct allocation
page read and write
355A000
direct allocation
page read and write
7986000
direct allocation
page read and write
74F4000
direct allocation
page read and write
7100000
direct allocation
page read and write
2880000
heap
page read and write
2A88000
heap
page read and write
3B08000
direct allocation
page read and write
58B9000
heap
page read and write
5550000
trusted library allocation
page read and write
7DD2000
direct allocation
page read and write
32F0000
heap
page read and write
289A000
heap
page read and write
712C000
direct allocation
page read and write
2BFE000
direct allocation
page read and write
6FEC000
direct allocation
page read and write
2C47000
direct allocation
page read and write
58C8000
heap
page read and write
41E8000
direct allocation
page read and write
58D8000
heap
page read and write
430C000
direct allocation
page read and write
4D0D000
heap
page read and write
319E000
direct allocation
page read and write
7C78000
direct allocation
page read and write
461E000
stack
page read and write
2C6C000
direct allocation
page read and write
3E82000
direct allocation
page read and write
2D56000
direct allocation
page read and write
5542000
heap
page read and write
5562000
heap
page read and write
5116000
heap
page read and write
5305000
heap
page read and write
78B4000
direct allocation
page read and write
2C3E000
direct allocation
page read and write
7966000
direct allocation
page read and write
3E38000
direct allocation
page read and write
408A000
direct allocation
page read and write
6CDE000
direct allocation
page read and write
78F2000
direct allocation
page read and write
58B9000
heap
page read and write
77C8000
direct allocation
page read and write
58E8000
heap
page read and write
5550000
trusted library allocation
page read and write
4ADD000
heap
page read and write
29CE000
heap
page read and write
2CE8000
direct allocation
page read and write
4D3F000
heap
page read and write
4A6B000
heap
page read and write
4D29000
heap
page read and write
202E000
unkown
page read and write
30C5000
heap
page read and write
4D53000
heap
page read and write
52FB000
heap
page read and write
3E00000
direct allocation
page read and write
2D5A000
direct allocation
page read and write
7860000
direct allocation
page read and write
2884000
direct allocation
page read and write
4AB5000
heap
page read and write
7F14000
direct allocation
page read and write
1128000
unkown
page execute read
4D4A000
heap
page read and write
4AE2000
heap
page read and write
749A000
direct allocation
page read and write
2836000
direct allocation
page read and write
58EC000
heap
page read and write
4D3F000
heap
page read and write
4715000
direct allocation
page read and write
3868000
direct allocation
page read and write
7938000
direct allocation
page read and write
58F4000
heap
page read and write
70EE000
direct allocation
page read and write
55E7000
heap
page read and write
2F82000
direct allocation
page read and write
52D7000
heap
page read and write
2A7E000
heap
page read and write
4D27000
heap
page read and write
6D00000
direct allocation
page read and write
705A000
direct allocation
page read and write
7AFA000
direct allocation
page read and write
546C000
heap
page read and write
28BA000
heap
page read and write
5304000
heap
page read and write
3A2A000
direct allocation
page read and write
287B000
heap
page read and write
2A61000
heap
page read and write
28B5000
heap
page read and write
2AB0000
heap
page read and write
532C000
heap
page read and write
6FEE000
direct allocation
page read and write
52E1000
heap
page read and write
2C15000
direct allocation
page read and write
28B6000
heap
page read and write
29EA000
heap
page read and write
5337000
heap
page read and write
28AE000
heap
page read and write
2A70000
heap
page read and write
10E5000
unkown
page execute read
4CAE000
stack
page read and write
289F000
direct allocation
page read and write
2A70000
heap
page read and write
7D1E000
direct allocation
page read and write
715A000
direct allocation
page read and write
4AE0000
heap
page read and write
4408000
direct allocation
page read and write
6AA2000
direct allocation
page read and write
79A2000
direct allocation
page read and write
4D21000
heap
page read and write
7CC8000
direct allocation
page read and write
28BE000
heap
page read and write
461A000
direct allocation
page read and write
58F4000
heap
page read and write
5AD4000
heap
page read and write
58E8000
heap
page read and write
4AC6000
heap
page read and write
55E4000
heap
page read and write
7A74000
direct allocation
page read and write
6AF4000
direct allocation
page read and write
4D53000
heap
page read and write
4D53000
heap
page read and write
2A5F000
heap
page read and write
5C5A000
heap
page read and write
7391000
direct allocation
page read and write
4AAB000
heap
page read and write
50AA000
heap
page read and write
2A95000
heap
page read and write
52D7000
heap
page read and write
3EF4000
direct allocation
page read and write
439A000
direct allocation
page read and write
50DB000
heap
page read and write
573C000
heap
page read and write
5116000
heap
page read and write
4D53000
heap
page read and write
7686000
direct allocation
page read and write
4340000
heap
page read and write
7112000
direct allocation
page read and write
4D63000
heap
page read and write
38A8000
direct allocation
page read and write
58C9000
heap
page read and write
4F18000
heap
page read and write
50EA000
heap
page read and write
5100000
heap
page read and write
7954000
direct allocation
page read and write
7A2E000
direct allocation
page read and write
6DB6000
direct allocation
page read and write
39E0000
direct allocation
page read and write
2FC8000
direct allocation
page read and write
2A8C000
heap
page read and write
3FAC000
direct allocation
page read and write
2F70000
direct allocation
page read and write
4AF7000
heap
page read and write
58F4000
heap
page read and write
7206000
direct allocation
page read and write
4AAE000
heap
page read and write
52D8000
heap
page read and write
67E6000
direct allocation
page read and write
754D000
direct allocation
page read and write
727C000
direct allocation
page read and write
5106000
heap
page read and write
288D000
heap
page read and write
677A000
direct allocation
page read and write
2F9C000
direct allocation
page read and write
438C000
stack
page read and write
30B7000
direct allocation
page read and write
58F4000
heap
page read and write
4D54000
heap
page read and write
45F4000
direct allocation
page read and write
516B000
heap
page read and write
5198000
heap
page read and write
50FF000
heap
page read and write
6A86000
direct allocation
page read and write
8BE000
stack
page read and write
4EFE000
stack
page read and write
58C8000
heap
page read and write
28A2000
heap
page read and write
4D1A000
heap
page read and write
7D66000
direct allocation
page read and write
5B16000
heap
page read and write
2C20000
direct allocation
page read and write
7140000
direct allocation
page read and write
6B66000
direct allocation
page read and write
568B000
heap
page read and write
5471000
heap
page read and write
7180000
direct allocation
page read and write
63C000
stack
page read and write
37D6000
direct allocation
page read and write
3CE8000
direct allocation
page read and write
3E26000
direct allocation
page read and write
7D9E000
direct allocation
page read and write
38B2000
direct allocation
page read and write
42F8000
direct allocation
page read and write
438C000
direct allocation
page read and write
451E000
direct allocation
page read and write
4D72000
heap
page read and write
4B4A000
heap
page read and write
7814000
direct allocation
page read and write
2076000
unkown
page read and write
756E000
direct allocation
page read and write
28A3000
heap
page read and write
50FA000
heap
page read and write
32BE000
heap
page read and write
5920000
heap
page read and write
4AAC000
heap
page read and write
21FD000
stack
page read and write
32DD000
heap
page read and write
4AF3000
heap
page read and write
58F4000
heap
page read and write
32DE000
heap
page read and write
3E78000
direct allocation
page read and write
58F4000
heap
page read and write
4AA7000
heap
page read and write
47C2000
direct allocation
page read and write
2C45000
direct allocation
page read and write
4D66000
heap
page read and write
29CC000
direct allocation
page read and write
6E50000
direct allocation
page read and write
28A3000
heap
page read and write
532C000
heap
page read and write
530D000
heap
page read and write
5761000
heap
page read and write
79D2000
direct allocation
page read and write
4AE0000
heap
page read and write
4ABB000
heap
page read and write
4D4A000
heap
page read and write
4A64000
heap
page read and write
4B5D000
heap
page read and write
6B26000
direct allocation
page read and write
4206000
direct allocation
page read and write
28BA000
heap
page read and write
771A000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
69B6000
direct allocation
page read and write
235FF000
stack
page read and write
3DDC000
direct allocation
page read and write
5A13000
heap
page read and write
6AEC000
direct allocation
page read and write
2C36000
direct allocation
page read and write
58B9000
heap
page read and write
4ACC000
heap
page read and write
4D53000
heap
page read and write
28B6000
heap
page read and write
6B60000
direct allocation
page read and write
289C000
heap
page read and write
6966000
direct allocation
page read and write
786E000
direct allocation
page read and write
2D82000
direct allocation
page read and write
4AA0000
heap
page read and write
73E2000
direct allocation
page read and write
6AA8000
direct allocation
page read and write
3190000
direct allocation
page read and write
532C000
heap
page read and write
2C7C000
direct allocation
page read and write
57E1000
heap
page read and write
4A6D000
heap
page read and write
4D29000
heap
page read and write
37F6000
direct allocation
page read and write
2A67000
heap
page read and write
2CCC000
direct allocation
page read and write
6B9B000
direct allocation
page read and write
50FA000
heap
page read and write
510E000
heap
page read and write
4D59000
heap
page read and write
5C37000
direct allocation
page read and write
705A000
direct allocation
page read and write
66FE000
direct allocation
page read and write
69A6000
direct allocation
page read and write
7AC4000
direct allocation
page read and write
22DFE000
stack
page read and write
4D27000
heap
page read and write
79C6000
direct allocation
page read and write
6CEA000
direct allocation
page read and write
28A6000
heap
page read and write
2CD2000
direct allocation
page read and write
5BF6000
direct allocation
page read and write
2A70000
heap
page read and write
515B000
heap
page read and write
530F000
heap
page read and write
52DC000
heap
page read and write
770A000
direct allocation
page read and write
4820000
direct allocation
page read and write
32F2000
heap
page read and write
58C8000
heap
page read and write
475E000
direct allocation
page read and write
78A6000
direct allocation
page read and write
58E8000
heap
page read and write
4D53000
heap
page read and write
712E000
direct allocation
page read and write
55B5000
heap
page read and write
43BF000
direct allocation
page read and write
52D7000
heap
page read and write
318C000
stack
page read and write
57DF000
heap
page read and write
4D0E000
heap
page read and write
58C8000
heap
page read and write
7514000
direct allocation
page read and write
694E000
direct allocation
page read and write
58D8000
heap
page read and write
7E52000
direct allocation
page read and write
28B9000
heap
page read and write
558B000
stack
page read and write
3EEC000
direct allocation
page read and write
5816000
heap
page read and write
3662000
direct allocation
page read and write
28A5000
heap
page read and write
28BA000
direct allocation
page read and write
4D1D000
heap
page read and write
3676000
direct allocation
page read and write
7526000
direct allocation
page read and write
4B11000
heap
page read and write
4894000
direct allocation
page read and write
4A7B000
heap
page read and write
7234000
direct allocation
page read and write
757A000
direct allocation
page read and write
6CDA000
direct allocation
page read and write
46E9000
direct allocation
page read and write
4D27000
heap
page read and write
69B8000
direct allocation
page read and write
4D0D000
heap
page read and write
58D9000
heap
page read and write
58E0000
heap
page read and write
2FFE000
direct allocation
page read and write
4D27000
heap
page read and write
1808000
unkown
page read and write
52DC000
heap
page read and write
730A000
direct allocation
page read and write
6C80000
direct allocation
page read and write
58ED000
heap
page read and write
414C000
direct allocation
page read and write
3784000
direct allocation
page read and write
4D63000
heap
page read and write
180F000
unkown
page read and write
2BEC000
direct allocation
page read and write
731E000
direct allocation
page read and write
5C9D000
direct allocation
page read and write
58E8000
heap
page read and write
6FC0000
direct allocation
page read and write
32FC000
heap
page read and write
532C000
heap
page read and write
795A000
direct allocation
page read and write
2C52000
direct allocation
page read and write
3AF6000
direct allocation
page read and write
7B00000
direct allocation
page read and write
2880000
heap
page read and write
78C1000
direct allocation
page read and write
6C38000
direct allocation
page read and write
6720000
direct allocation
page read and write
2B9C000
direct allocation
page read and write
4771000
direct allocation
page read and write
58E8000
heap
page read and write
5116000
heap
page read and write
4066000
direct allocation
page read and write
4D27000
heap
page read and write
4D1B000
heap
page read and write
2D98000
direct allocation
page read and write
7AD4000
direct allocation
page read and write
4B07000
heap
page read and write
C00000
direct allocation
page read and write
6A96000
direct allocation
page read and write
225A000
direct allocation
page read and write
4CE3000
heap
page read and write
2A6C000
heap
page read and write
3634000
direct allocation
page read and write
68A6000
direct allocation
page read and write
47C4000
direct allocation
page read and write
2A71000
heap
page read and write
28A6000
heap
page read and write
41A8000
direct allocation
page read and write
532D000
heap
page read and write
2D40000
direct allocation
page read and write
39CE000
direct allocation
page read and write
5379000
heap
page read and write
4750000
remote allocation
page read and write
6E84000
direct allocation
page read and write
5704000
direct allocation
page read and write
4B13000
heap
page read and write
7E90000
direct allocation
page read and write
3A9A000
direct allocation
page read and write
28B5000
heap
page read and write
5288000
heap
page read and write
1115000
unkown
page execute read
2C12000
direct allocation
page read and write
3EBA000
direct allocation
page read and write
70DC000
direct allocation
page read and write
7138000
direct allocation
page read and write
2C14000
direct allocation
page read and write
2C88000
direct allocation
page read and write
58EC000
heap
page read and write
75D4000
direct allocation
page read and write
3DE6000
direct allocation
page read and write
4A7C000
heap
page read and write
2D2E000
direct allocation
page read and write
546E000
heap
page read and write
306C000
direct allocation
page read and write
306D000
direct allocation
page read and write
6E10000
direct allocation
page read and write
42A8000
direct allocation
page read and write
7C15000
direct allocation
page read and write
35FC000
direct allocation
page read and write
4A81000
heap
page read and write
7BBE000
direct allocation
page read and write
3B04000
direct allocation
page read and write
24A5D000
stack
page read and write
2880000
heap
page read and write
510A000
heap
page read and write
58B9000
heap
page read and write
4D15000
heap
page read and write
5344000
heap
page read and write
4880000
direct allocation
page read and write
70DE000
direct allocation
page read and write
50FF000
heap
page read and write
4AB4000
heap
page read and write
58F4000
heap
page read and write
7936000
direct allocation
page read and write
6B12000
direct allocation
page read and write
2C38000
direct allocation
page read and write
373E000
direct allocation
page read and write
791E000
direct allocation
page read and write
532C000
heap
page read and write
58F4000
heap
page read and write
4296000
direct allocation
page read and write
4A64000
heap
page read and write
4D27000
heap
page read and write
28F2000
direct allocation
page read and write
532F000
heap
page read and write
4900000
direct allocation
page read and write
55B9000
heap
page read and write
5C8B000
direct allocation
page read and write
58F4000
heap
page read and write
305E000
direct allocation
page read and write
4196000
direct allocation
page read and write
58D8000
heap
page read and write
5577000
heap
page read and write
28B5000
heap
page read and write
4EE1000
heap
page read and write
3E82000
direct allocation
page read and write
1199000
unkown
page execute read
4D3F000
heap
page read and write
433F000
direct allocation
page read and write
58C9000
heap
page read and write
32E7000
heap
page read and write
4D3F000
heap
page read and write
3090000
unkown
page read and write
6A64000
direct allocation
page read and write
3BF4000
direct allocation
page read and write
44D4000
direct allocation
page read and write
6986000
direct allocation
page read and write
6B48000
direct allocation
page read and write
287B000
heap
page read and write
2AC0000
direct allocation
page read and write
6B22000
direct allocation
page read and write
6D94000
direct allocation
page read and write
2A6C000
heap
page read and write
50EA000
heap
page read and write
7C86000
direct allocation
page read and write
58D8000
heap
page read and write
4D12000
heap
page read and write
58A4000
heap
page read and write
50DB000
heap
page read and write
4D92000
heap
page read and write
7084000
direct allocation
page read and write
7538000
direct allocation
page read and write
47BD000
stack
page read and write
58C9000
heap
page read and write
77C2000
direct allocation
page read and write
4D53000
heap
page read and write
3A42000
direct allocation
page read and write
295A000
direct allocation
page read and write
50DB000
heap
page read and write
58D8000
heap
page read and write
7E40000
direct allocation
page read and write
58C8000
heap
page read and write
58E8000
heap
page read and write
2AAE000
heap
page read and write
4D8E000
heap
page read and write
52DE000
heap
page read and write
2C3E000
direct allocation
page read and write
70A4000
direct allocation
page read and write
7E66000
direct allocation
page read and write
4309000
direct allocation
page read and write
5C14000
direct allocation
page read and write
2826000
direct allocation
page read and write
4D3F000
heap
page read and write
2DCC000
direct allocation
page read and write
2A6C000
heap
page read and write
4D2B000
heap
page read and write
3094000
direct allocation
page read and write
4F60000
trusted library allocation
page read and write
7A0A000
direct allocation
page read and write
28BE000
heap
page read and write
37E0000
direct allocation
page read and write
24D20000
direct allocation
page read and write
29F3000
heap
page read and write
2D42000
direct allocation
page read and write
4D63000
heap
page read and write
310E000
direct allocation
page read and write
79B0000
direct allocation
page read and write
7806000
direct allocation
page read and write
53A9000
heap
page read and write
9EE000
stack
page read and write
5321000
heap
page read and write
58E8000
heap
page read and write
5BE6000
heap
page read and write
326A000
heap
page read and write
28B9000
heap
page read and write
478C000
direct allocation
page read and write
4D59000
heap
page read and write
CC0000
unkown
page readonly
58B9000
heap
page read and write
2892000
heap
page read and write
231FF000
stack
page read and write
3794000
direct allocation
page read and write
32D5000
heap
page read and write
441A000
direct allocation
page read and write
32A4000
heap
page read and write
2955000
direct allocation
page read and write
58EC000
heap
page read and write
52EF000
heap
page read and write
58F4000
heap
page read and write
5683000
heap
page read and write
2838000
direct allocation
page read and write
4D4A000
heap
page read and write
2FC0000
direct allocation
page read and write
5086000
heap
page read and write
5726000
heap
page read and write
375E000
direct allocation
page read and write
58EC000
heap
page read and write
510A000
heap
page read and write
510A000
heap
page read and write
2A95000
heap
page read and write
5062000
heap
page read and write
52D9000
heap
page read and write
5776000
heap
page read and write
4CD0000
heap
page read and write
4AF7000
heap
page read and write
52DD000
heap
page read and write
4AF7000
heap
page read and write
72C4000
direct allocation
page read and write
4B08000
heap
page read and write
28A6000
heap
page read and write
30C7000
heap
page read and write
5AB4000
heap
page read and write
4D61000
heap
page read and write
3726000
direct allocation
page read and write
4A64000
heap
page read and write
4386000
direct allocation
page read and write
6E54000
direct allocation
page read and write
4AAE000
heap
page read and write
754A000
direct allocation
page read and write
2C50000
direct allocation
page read and write
74F4000
direct allocation
page read and write
4D1A000
heap
page read and write
289C000
direct allocation
page read and write
4D5F000
heap
page read and write
2898000
heap
page read and write
22FFF000
stack
page read and write
6FB8000
direct allocation
page read and write
411C000
direct allocation
page read and write
7872000
direct allocation
page read and write
2830000
direct allocation
page read and write
2320000
direct allocation
page read and write
4AC6000
heap
page read and write
1D70000
direct allocation
page read and write
4D53000
heap
page read and write
2EB6000
direct allocation
page read and write
3694000
direct allocation
page read and write
3014000
direct allocation
page read and write
52CF000
heap
page read and write
4D29000
heap
page read and write
503D000
heap
page read and write
32F2000
heap
page read and write
4D53000
heap
page read and write
4D53000
heap
page read and write
4D2C000
heap
page read and write
3918000
direct allocation
page read and write
58DE000
heap
page read and write
4AB9000
heap
page read and write
5CCB000
direct allocation
page read and write
799C000
direct allocation
page read and write
4D29000
heap
page read and write
58E8000
heap
page read and write
4250000
direct allocation
page read and write
2D4E000
direct allocation
page read and write
4AC6000
heap
page read and write
58C8000
heap
page read and write
4ACD000
heap
page read and write
7902000
direct allocation
page read and write
6B1A000
direct allocation
page read and write
4AC6000
heap
page read and write
58D8000
heap
page read and write
58F4000
heap
page read and write
5489000
stack
page read and write
4D53000
heap
page read and write
35A4000
direct allocation
page read and write
373A000
direct allocation
page read and write
502A000
heap
page read and write
4272000
direct allocation
page read and write
7D30000
direct allocation
page read and write
4AA7000
heap
page read and write
9A6000
heap
page read and write
4A61000
heap
page read and write
5770000
direct allocation
page read and write
50EA000
heap
page read and write
2FE4000
direct allocation
page read and write
4354000
direct allocation
page read and write
2CCC000
direct allocation
page read and write
2E00000
direct allocation
page read and write
4606000
direct allocation
page read and write
6992000
direct allocation
page read and write
58B9000
heap
page read and write
6E44000
direct allocation
page read and write
28A2000
heap
page read and write
5562000
heap
page read and write
532F000
heap
page read and write
7342000
direct allocation
page read and write
3770000
direct allocation
page read and write
4A7C000
heap
page read and write
7378000
direct allocation
page read and write
531C000
heap
page read and write
5CD1000
direct allocation
page read and write
5CBB000
direct allocation
page read and write
422A000
direct allocation
page read and write
4D4A000
heap
page read and write
4AA7000
heap
page read and write
46EC000
direct allocation
page read and write
52DF000
heap
page read and write
2ABD000
stack
page read and write
5998000
heap
page read and write
79FE000
direct allocation
page read and write
5550000
trusted library allocation
page read and write
32D5000
heap
page read and write
532C000
heap
page read and write
7678000
direct allocation
page read and write
52CF000
heap
page read and write
58F4000
heap
page read and write
4579000
direct allocation
page read and write
5680000
heap
page read and write
3558000
direct allocation
page read and write
43DE000
direct allocation
page read and write
28BC000
heap
page read and write
289F000
heap
page read and write
32B9000
heap
page read and write
562E000
heap
page read and write
32E3000
heap
page read and write
486A000
direct allocation
page read and write
58C9000
heap
page read and write
4D4A000
heap
page read and write
5302000
heap
page read and write
5362000
heap
page read and write
71A6000
direct allocation
page read and write
6758000
direct allocation
page read and write
76BC000
direct allocation
page read and write
4736000
direct allocation
page read and write
4336000
direct allocation
page read and write
32D9000
heap
page read and write
2D7E000
direct allocation
page read and write
5C40000
direct allocation
page read and write
4D27000
heap
page read and write
7366000
direct allocation
page read and write
2877000
heap
page read and write
50EA000
heap
page read and write
2954000
direct allocation
page read and write
9DE000
stack
page read and write
5102000
heap
page read and write
4D4A000
heap
page read and write
980000
direct allocation
page read and write
431C000
direct allocation
page read and write
3714000
direct allocation
page read and write
4D1D000
heap
page read and write
226C000
heap
page read and write
58EC000
heap
page read and write
3282000
direct allocation
page read and write
6EA8000
direct allocation
page read and write
5305000
heap
page read and write
388F000
direct allocation
page read and write
3E4A000
direct allocation
page read and write
32E0000
heap
page read and write
69EE000
direct allocation
page read and write
52DC000
heap
page read and write
229FF000
stack
page read and write
4D3F000
heap
page read and write
5324000
heap
page read and write
4D27000
heap
page read and write
4AC6000
heap
page read and write
6A58000
direct allocation
page read and write
4AC5000
heap
page read and write
5324000
heap
page read and write
3B2E000
direct allocation
page read and write
5868000
heap
page read and write
319A000
direct allocation
page read and write
66B4000
direct allocation
page read and write
3AE0000
direct allocation
page read and write
44B0000
direct allocation
page read and write
58A4000
heap
page read and write
58F4000
heap
page read and write
30C9000
heap
page read and write
4AAE000
heap
page read and write
4AC6000
heap
page read and write
50CA000
heap
page read and write
4AB9000
heap
page read and write
7948000
direct allocation
page read and write
6D90000
direct allocation
page read and write
2870000
heap
page read and write
2A92000
heap
page read and write
52D7000
heap
page read and write
2BC4000
direct allocation
page read and write
3972000
direct allocation
page read and write
4A7C000
heap
page read and write
5116000
heap
page read and write
2A61000
heap
page read and write
4A81000
heap
page read and write
3062000
direct allocation
page read and write
4D4A000
heap
page read and write
369C000
direct allocation
page read and write
560C000
stack
page read and write
2C02000
direct allocation
page read and write
4739000
direct allocation
page read and write
4366000
direct allocation
page read and write
579D000
heap
page read and write
41F2000
direct allocation
page read and write
2F9E000
direct allocation
page read and write
532D000
heap
page read and write
2AA8000
heap
page read and write
29D3000
heap
page read and write
4D4A000
heap
page read and write
73DB000
direct allocation
page read and write
3A70000
direct allocation
page read and write
7214000
direct allocation
page read and write
6AB4000
direct allocation
page read and write
711A000
direct allocation
page read and write
4D3F000
heap
page read and write
2900000
remote allocation
page read and write
30A4000
direct allocation
page read and write
2845000
direct allocation
page read and write
2A70000
heap
page read and write
7000000
direct allocation
page read and write
32DE000
heap
page read and write
45D8000
direct allocation
page read and write
6CC6000
direct allocation
page read and write
2EDF000
direct allocation
page read and write
42B6000
direct allocation
page read and write
1104000
unkown
page execute read
2A61000
heap
page read and write
2893000
heap
page read and write
4DCE000
heap
page read and write
672A000
direct allocation
page read and write
510E000
heap
page read and write
30F6000
direct allocation
page read and write
There are 4835 hidden memdumps, click here to show them.