• Nenhum resultado encontrado

Report #13925

N/A
N/A
Protected

Academic year: 2023

Share "Report #13925"

Copied!
84
0
0

Texto

(1)

Binary

DLL False

Size 5.35MB

trid 61.7% Win64 Executable

14.7% Win32 Dynamic Link Library 10.0% Win32 Executable

4.5% OS/2 Executable

4.4% Generic Win/DOS Executable

type PE

wordsize 64

Subsystem Windows CLI

Hashes

md5 bb0e954eea8d2c802488b2e01221752a

sha1 151af06362ab47e33112860b152c67e668e22582

crc32 0x460a025f

sha224 b51aed6f3c093b0e411a303bc1e2633db11cd32a39d3c0f40d3eb318 sha256 f57891fe23b8120e1371f1221ffb9f504b172f09f18bf2852f65e0ec500236bd

sha384 7e9b1c5bb707d2fced8abae8259311f6ee2b64b9214875beb4c989ffe8ebf9 495e77ea08255ad0a2305e3a69d7728a13

Creation Date: Aug. 3, 2022, 10:10 p.m.

Last Update: Aug. 3, 2022, 10:14 p.m.

File:

evader.exe Results:

(2)

YARA

Matches IP, ThreadControl__Context, CRC16_table, HasDebugData, CRC32_poly_Con stant, BASE64_table, HasRichSignature, RIPEMD160_Constants, CRC32_tabl e, network_dns, CRC32b_poly_Constant, IsPacked, Microsoft_Visual_Cpp_80 _DLL, antivm_vmware, contentis_base64, network_tcp_socket, Misc_Suspici ous_Strings, win_hook, win_mutex, keylogger, VirtualPC_Detection, maldoc_

find_kernel32_base_method_1, vmdetect, anti_dbg, antisb_threatExpert, wi n_files_operation, SHA512_Constants, network_tcp_listen, DebuggerHiding_

_Active, url, SHA1_Constants, android_meterpreter, win_registry, IsPE64, Is Console, network_dga, Advapi_Hash_API, MD5_Constants, System_Tools, Bi g_Numbers1

Suspicious True

Imports

GDI32.dll ExtCreatePen, MoveToEx, GetTextExtentPoint32W, GetTextMetricsW, LineTo, SetTextColor, DeleteDC, CreateDIBSection, CreateFontIndirectW, GetDevice Caps, SetBkColor, GetRgnBox, SetBkMode, SelectObject, SetRectRgn, Creat eCompatibleDC, CreateRectRgnIndirect, CombineRgn, CreateSolidBrush, Eq ualRgn, GetStockObject, CreatePatternBrush, CreateRectRgn, GetObjectW, GetTextExtentPointW, CreateCompatibleBitmap

WINMM.dll timeGetTime

ole32.dll CoInitialize, CoUninitialize, CoCreateInstance RPCRT4.dll UuidToStringW, RpcStringFreeW, UuidCreate SHELL32.dll SHGetSpecialFolderPathW, ShellAboutW UxTheme.dll IsThemeActive, BufferedPaintClear

ADVAPI32.dll RegEnumKeyExW, RegQueryValueExW, RegQueryInfoKeyW, RegDeleteKey W, RegSetValueExW, RegCloseKey, RegCreateKeyW, RegOpenKeyExW, Reg EnumValueW, RegGetValueW

(3)

OLEAUT32.dll BSTR_UserFree

Strings

List

MTA:SA Server %s - See http://mtasa.com/agent/

zip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll unzip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll

# https://curl.se/docs/http-cookies.html

http://updatesa.multitheftauto.com/sa/trouble/?v=_VERSION_&id=_ID_&tr=_TROUBLE_

ftp@example.com

# Your alt-svc cache. https://curl.se/docs/alt-svc.html

# Your HSTS cache. https://curl.se/docs/hsts.html

!http://crl.certum.pl/cscasha2.crl0q http://cscasha2.ocsp-certum.com04 (http://repository.certum.pl/cscasha2.cer0

C:\BuildAgent\work\675e5b8e8f135823\Build\Symbols\Client Network.pdb

c:\Users\Win\Documents\Visual Studio 2012\Projects\Dropper\x64\Release\Dropper.pdb Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0

C:\BuildAgent\work\675e5b8e8f135823\Client\net\raknet\CCryptRC4.hpp H.iR

C:\BuildAgent\work\675e5b8e8f135823\Shared\sdk\net\CNetHTTPDownloadManagerInterface.h https://www.certum.pl/CPS0

http://www.certum.pl/CPS0 http://www.certum.pl/CPS0 http://www.certum.pl/CPS0 http://www.certum.pl/CPS0 http://crl.certum.pl/ctnca2.crl0l http://crl.certum.pl/ctnca.crl0k http://crl.certum.pl/ctnca.crl0k

%http://repository.certum.pl/ctnca.cer09

%http://repository.certum.pl/ctnca.cer09

&http://repository.certum.pl/ctnca2.cer09 )http://repository.certum.pl/ctsca2021.cer0@

"http://crl.certum.pl/ctsca2021.crl0o http://%s

http://subca.ocsp-certum.com02 http://subca.ocsp-certum.com05 http://subca.ocsp-certum.com01 http://subca.ocsp-certum.com01

C:\BuildAgent\work\675e5b8e8f135823\Shared\sdk\WString.hpp

C:\BuildAgent\work\675e5b8e8f135823\Shared\sdk\SharedUtil.Profiling.hpp C:\BuildAgent\work\675e5b8e8f135823\Shared\sdk\SharedUtil.Misc.hpp C:\BuildAgent\work\675e5b8e8f135823\Shared\sdk\SString.hpp

(4)

[HTTPDownload] %s Invalid file descriptors. [cfds:%d]

file://%s%s%s E.Be

5.Af y.LR jB.li 127.0.0.1 CRYPT32.dll security.dll proxy_sa.exe

CONNECT %s HTTP/%s

ERROR_HOTKEY_NOT_REGISTERED

ERROR_DS_SAM_NEED_BOOTKEY_PASSWORD HTTP/%1d.%1d%c%3d%c

ERROR_HOTKEY_ALREADY_REGISTERED V.JO

Q.Aq M.Jm A.CZ

HTTP/1.%d %d HTTP/%1[23] %d HTTP/%s

5.cz z.gq HTTP %3d

Unsupported proxy '%s', libcurl is built without the HTTPS-proxy support.

Establish HTTP proxy tunnel to %s:%d

SEC_E_ILLEGAL_MESSAGE (0x%08X) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handsha ke failed). More detail may be available in the Windows System event log.

report.log COMCTL32.dll MSVCR110.dll WS2_32.dll WININET.dll ,&combase.dll WINTRUST.dll data\surfaud.dat WINMM.dll WINMM.dll UxTheme.dll iphlpapi.dll dbghelp.dll pthread.dll core.dll

mta\core2.dmp netc.dll

ntdll.dll

(5)

Heuristics

IPs hasIPs: True

Allowed: 127.0.0.1, 1, localhost.

Suspicious: 2.5.4.8, 0, Unknown, 2.5.4.9, 0, Unknown, 2.5.4.6, 0, Unknown , 2.5.4.7, 0, Unknown, 2.5.4.4, 0, Unknown, 2.5.4.5, 0, Unknown, 2.5.4.3, 0, Unknown, 2.5.4.72, 0, Unknown, 1.2.0.4, 0, Unknown, 2.5.4.10, 0, Unknown , 2.5.4.11, 0, Unknown, 2.5.4.12, 0, Unknown, 2.5.4.13, 0, Unknown, 2.5.4.1 7, 0, Unknown, 1.3.14.3, 0, Unknown, 2.5.4.45, 0, Unknown, 101.3.4.2, 0, U nknown, 2.5.4.44, 0, Unknown, 2.5.4.65, 0, Unknown, 2.5.29.17, 0, Unknow n, 2.5.4.46, 0, Unknown, 2.5.29.18, 0, Unknown, 2.5.29.19, 0, Unknown, 2.5 .4.43, 0, Unknown, 2.5.4.42, 0, Unknown, 2.5.4.41, 0, Unknown

hasAllowed: True hasSuspicious: True

URLs Allowed: http://crl.microsoft.com/pki/crl/products/microsoftcodeverifroot.cr l0

hasURLs: True

Suspicious: http://crl.certum.pl/ctsca2021.crl0o, http://repository.certum.p l/cscasha2.cer0, http://repository.certum.pl/ctsca2021.cer0@, http://subca.o csp-certum.com05, file://%s%s%s, http://subca.ocsp-certum.com02, http://s ubca.ocsp-certum.com01, http://cscasha2.ocsp-certum.com04, http://, http:

//updatesa.multitheftauto.com/sa/trouble/?v=_version_&id=_id_&tr=_troubl e_, http://crl.certum.pl/cscasha2.crl0q, https://curl.se/docs/hsts.html, http://

www.certum.pl/cps0, http://mtasa.com/agent/, https://curl.se/docs/http-coo kies.html, file://, https://www.certum.pl/cps0, http://www.winimage.com/zlib dll, http://%s, http://repository.certum.pl/ctnca.cer09, http://crl.certum.pl/ct nca2.crl0l, https://curl.se/docs/alt-svc.html, http://repository.certum.pl/ctnc a2.cer09, https://, http://crl.certum.pl/ctnca.crl0k

hasAllowed: True hasSuspicious: True

Files Allowed: api-ms-win-core-synch-l1-2-0.dll, dbghelp.dll, mscoree.dll, kernel 32.dll, ADVAPI32.dll, RPCRT4.dll, pthread.dll, SHELL32.dll, USER32.dll, WINT RUST.dll, secur32.dll, UxTheme.dll, ntdll.dll, MSVCR110.dll, COMCTL32.dll, I PHLPAPI.DLL, ,&combase.dll, WINMM.dll, SHLWAPI.dll, security.dll, WS2_32.d ll, OLEAUT32.dll, WININET.dll, Normaliz.dll, ole32.dll, CRYPT32.dll, core.dll, n etc.dll, GDI32.dll

hasFiles: True

Suspicious: =J.So, %s.%s.tmp, report.log, E*6.Jar, data\surfaud.dat, TIMEC YC.DAT

hasAllowed: True hasSuspicious: True

(6)

Address: 5368709120 Suspicious: False Stack

Stack: 4096 Suspicious: False Headers

Headers: 1024 Suspicious: False Suspicious: False

Symbols Number

Number: 0

Suspicious: True Pointer

Pointer: 0

Suspicious: True Directories Number: 16 Suspicious: False

Checksum Value: 0

Suspicous: True

Sections Allowed: .text, .rdata, .data, .pdata, .rsrc, .reloc Suspicious

hasAllowed: True hasSections: True hasSuspicious: False

Versions OS

Version: 6

Suspicious: False Image

Version: True Suspicious: 6 Linker

Version: 11.0 Suspicious: False Subsystem

Version: 6.0 Suspicious: False Suspicious: False

(7)

2_32.dll, oleaut32.dll, wininet.dll, normaliz.dll, ole32.dll, crypt32.dll, gdi32.d ll

hasLibs: True

Suspicious: pthread.dll, msvcr110.dll, iphlpapi.dll, ,&combase.dll, core.dll, netc.dll

hasAllowed: True hasSuspicious: True

Timestamp Past: False

Valid: True

Value: 2022-08-03 22:10:00 Future: False

Compilation Packed: False

Missing: False Packers

Compiled: True

Compilers: Microsoft Visual C++ 8.0 (DLL)

Obfuscation XOR: True

Fuzzing: True

PEDetector

Matches 12448

Suspicious True

Disassembly

hasTricks False

Tricks

AVclass

(8)

AVG result: Win64:BankerX-gen [Trj]

update: 20220804 version: 21.1.5827.0 detected: True

CMC update: 20220623

version: 2.10.2019.1 detected: False

MAX result: malware (ai score=88)

update: 20220804 version: 2019.9.16.1 detected: True

APEX result: Malicious

update: 20220801 version: 6.319 detected: True

Bkav update: 20220804

version: 1.3.0.9899 detected: False

K7GW result: Trojan ( 0057208f1 )

update: 20220803 version: 12.29.43670 detected: True

ALYac result: Gen:Variant.Johnnie.276394

update: 20220804 version: 1.1.3.1 detected: True

Avast result: Win64:BankerX-gen [Trj]

update: 20220804 version: 21.1.5827.0

(9)

Cynet result: Malicious (score: 100) update: 20220803

version: 4.0.0.27 detected: True

Cyren result: W64/Kryptik.BZP.gen!Eldorado

update: 20220804 version: 6.5.1.2 detected: True

DrWeb result: Trojan.Encoder.30162

update: 20220803 version: 7.0.56.4040 detected: True

GData result: Gen:Variant.Johnnie.276394

update: 20220804

version: A:25.33665B:27.28316 detected: True

Panda update: 20220803

version: 4.6.4.2 detected: False

VBA32 update: 20220803

version: 5.0.0 detected: False

VIPRE result: Gen:Variant.Johnnie.276394

update: 20220803 version: 6.0.0.35 detected: True

VirIT update: 20220803

version: 9.5.252 detected: False

(10)

Comodo update: 20220803 version: 34865 detected: False

Ikarus result: Trojan.Win32.Injector

update: 20220803 version: 6.0.26.0 detected: True

Lionic update: 20220803

version: 7.5 detected: False

McAfee update: 20220804

version: 6.0.6.653 detected: False

Rising result: Backdoor.Remcos!8.B89E (TFE:dGZlOgWqGCmoSHuGoQ) update: 20220803

version: 25.0.0.27 detected: True

Sophos update: 20220803

version: 1.4.1.0 detected: False

Yandex update: 20220725

version: 5.5.2.24 detected: False

Zillya update: 20220803

version: 2.0.0.4682 detected: False

Acronis update: 20220426

version: 1.2.0.108

(11)

Cylance update: 20220804 version: 2.3.1.101 detected: False

Elastic result: malicious (high confidence) update: 20220728

version: 4.0.41 detected: True

FireEye result: Generic.mg.bb0e954eea8d2c80

update: 20220803 version: 35.24.1.0 detected: True

Sangfor update: 20220803

version: 2.14.0.0 detected: False

TACHYON update: 20220803

version: 2022-08-03.02 detected: False

Tencent result: Malware.Win32.Gencirc.10ce3e28 update: 20220804

version: 1.0.0.1 detected: True

ViRobot update: 20220803

version: 2014.3.20.0 detected: False

Webroot update: 20220804

version: 1.0.0.403 detected: False

(12)

detected: True

F-Secure update: 20220803

version: 18.10.978.51 detected: False

Fortinet result: W32/Kryptik.HEUR!tr

update: 20220803 version: 6.4.258.0 detected: True

Jiangmin result: Trojan.MSIL.qkml

update: 20220730 version: 16.0.100 detected: True

Kingsoft update: 20220804

version: 2017.9.26.565 detected: False

Paloalto update: 20220804

version: 0.9.0.1003 detected: False

Symantec update: 20220803

version: 1.18.0.0 detected: False

Trapmine update: 20220707

version: 3.5.48.101 detected: False

AhnLab-V3 result: Trojan/Win32.AgentTesla.R350864 update: 20220804

(13)

detected: True

MaxSecure update: 20220801

version: 1.0.0.1 detected: False

Microsoft result: TrojanDropper:Win64/SodinokibiCrypt.SA!MTB update: 20220803

version: 1.1.19400.3 detected: True

ZoneAlarm update: 20220803

version: 1.0 detected: False

Cybereason result: malicious.eea8d2

update: 20210330 version: 1.2.449 detected: True

ESET-NOD32 result: a variant of Win64/Kryptik.CAA update: 20220803

version: 25700 detected: True

Gridinsoft result: Trojan.Win64.Kryptik.oa!s1 update: 20220804

version: 1.0.89.174 detected: True

TrendMicro update: 20220803

version: 11.0.0.1006 detected: False

BitDefender result: Gen:Variant.Johnnie.276394 update: 20220803

version: 7.2

(14)

SentinelOne update: 20220330 version: 22.2.1.2 detected: False

Malwarebytes result: Malware.AI.1160498980 update: 20220804

version: 4.3.3.37 detected: True

CAT-QuickHeal update: 20220803

version: 14.00 detected: False

NANO-Antivirus update: 20220803

version: 1.0.146.25618 detected: False

BitDefenderTheta update: 20220802

version: 7.2.37796.0 detected: False

MicroWorld-eScan result: Gen:Variant.Johnnie.276394 update: 20220803

version: 14.0.409.0 detected: True

SUPERAntiSpyware update: 20220730

version: 5.6.0.1032 detected: False

McAfee-GW-Edition update: 20220803 version: v2019.1.2+3728 detected: False

(15)

resource bb0e954eea8d2c802488b2e01221752a

permalink https://www.virustotal.com/gui/file/f57891fe23b8120e1371f1221ffb9f504b1 72f09f18bf2852f65e0ec500236bd/detection/f-f57891fe23b8120e1371f122 1ffb9f504b172f09f18bf2852f65e0ec500236bd-1659575410

positives 33

scan_date 2022-08-04 01:10:10

verbose_msg Scan finished, information embedded

response_code 1

File

Trace

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(16)

45:43.325 e 76 are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.325

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(17)

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.340

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(18)

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.356

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(19)

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.372

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(20)

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.387

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(21)

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(22)

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.403

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(23)

3/8/2022 - 21:

45:43.528

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(24)

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.543

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(25)

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.559

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(26)

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.575

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(27)

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.590

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(28)

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.606

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(29)

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.622

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(30)

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.700

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(31)

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.715

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(32)

45:43.731 e 76 are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.731

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(33)

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.747

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(34)

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(35)

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.762

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(36)

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.778

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(37)

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.793

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(38)

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.856

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(39)

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(40)

3/8/2022 - 21:

45:43.872

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(41)

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.887

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(42)

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.903

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(43)

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.918

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(44)

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(45)

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.934

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(46)

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:43.950

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

(47)

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.12

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

3/8/2022 - 21:

45:44.28

Writ e

24 76

C:\malw

are.exe C:\Monitor\proc.exe

Referências

Documentos relacionados

Files Allowed: USER32.DLL, kernel32.dll, mscoree.dll, combase.dll, ADVAPI32.dll , OLEAUT32.dll, VERSION.dll, UxTheme.dll, WSOCK32.dll, SHELL32.dll, PSAPI.DLL, COMCTL32.dll,

Files Allowed: ADVAPI32.dll, msvcrt.dll, ntdll.dll, NMM.dll, KERNEL32.dll, GDI32.d ll, USER32.dll. hasFiles: True

ws2_32.dll ws2_32.dll olepro32.dll comctl32.dll comctl32.dll comctl32.dll comctl32.dll comctl32.dll wship6.dll version.dll WINMM.dll UxTheme.dll wininet.dll uxtheme.dll 0.0.0.0

Files Allowed: kernel32.dll, USER32.dll, mscoree.dll, GDI32.dll hasFiles:

Libraries Allowed: mapi32.dll, mtxex.dll, ws2_32.dll, user32.dll, uxtheme.dll, dwmap i.dll, wininet.dll, ole32.dll, imm32.dll, advapi32.dll, comctl32.dll, shfolder.dll,

Files Allowed: rarext64.dll, rarext.dll, riched20.dll, KERNEL32.DLL, cabinet.dll, U nAceV2.Dll, Wkernel32.dll, mscoree.dll, \SOFTWARE\Microsoft\Windows\Curr

Files Allowed: user32.dll, kernel32.dll, uxtheme.dll, gdi32.dll, crypt32.dll, coleto r.dll, vcltest3.dll, pstorec.dll, MAPI32.DLL, version.dll, comctl32.dll, shell32.d ll,

Files Allowed: 2ntdll.dll, WININET.dll, shlwapi.dll, MSVCR110.dll, CRYPT32.dll, SH ELL32.dll, user32.dll, ADVAPI32.dll, PSAPI.DLL, kernel32.dll, GDI32.dll, msvc rt.dll,