PUP.BadJoke.PHA

The detection of PUP.BadJoke.PHA on your system indicates the presence of a potentially unwanted program (PUP) that may be causing issues with your computer's performance and security. It's essential to understand the nature of this threat and take immediate action to remove it to prevent any potential harm.

What Is PUP.BadJoke.PHA?

PUP.BadJoke.PHA is a type of malware that is classified as a potentially unwanted program. This means that while it may not be as harmful as other types of malware, such as viruses or Trojans, it can still cause problems with your system and compromise your personal data. PUPs are often installed on a system without the user's knowledge or consent, and they can be difficult to remove.

How PUP.BadJoke.PHA Operates

PUPs like PUP.BadJoke.PHA typically operate by installing themselves on a system through various means, such as bundled software downloads or exploit kits. Once installed, they can collect user data, display unwanted advertisements, and even install additional malware on the system. They can also modify system settings and registry entries, making it challenging to remove them completely.

It's worth noting that PUPs can be particularly tricky to detect, as they often masquerade as legitimate programs or system files. This is why it's crucial to have a reputable antivirus program installed on your system, as well as to practice safe browsing habits, such as avoiding suspicious downloads and links.

Symptoms of Infection

If your system is infected with PUP.BadJoke.PHA, you may notice a range of symptoms, including slow system performance, unwanted pop-ups and advertisements, and changes to your browser settings. You may also notice that your system is crashing or freezing frequently, or that your personal data is being collected and transmitted to unknown parties.

  • Unwanted advertisements and pop-ups
  • Slow system performance
  • Changes to browser settings
  • System crashes and freezes
  • Unexplained data collection and transmission

How to Remove PUP.BadJoke.PHA

  1. Boot your system in Safe Mode with Networking to prevent the PUP from loading and to allow for a clean removal process.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of PUP.BadJoke.PHA.
  3. Uninstall any suspicious programs that may be related to the PUP, taking care to read the uninstallation prompts carefully to ensure that you are not inadvertently uninstalling legitimate programs.
  4. Reset your browsers, including Chrome, Firefox, and Edge, to their default settings to remove any changes made by the PUP.
  5. Reboot your system and run another scan with your anti-malware tool to ensure that all instances of PUP.BadJoke.PHA have been removed.

Conclusion

Removing PUP.BadJoke.PHA from your system requires careful attention to detail and a thorough understanding of the removal process. By following the steps outlined above and taking proactive measures to protect your system, you can help prevent future infections and keep your personal data safe. Remember to always practice safe browsing habits and to keep your antivirus program up to date to ensure the best possible protection against malware and other online threats.

Analysis Report

General information

Family Name: PUP.BadJoke.PHA
Signature status: No Signature

Known Samples

MD5: cc1401e69a773e2f2cbadea117330d71
SHA1: ee9e15fe659d302c2ab6791570b6abb34b886259
File Size: 9.81 MB, 9806719 bytes
MD5: 0c5876db3d206fc52d9b953e4c8d7b29
SHA1: 7626f7d00368bcb967ec00582900c4b0412e9223
File Size: 8.05 MB, 8054268 bytes
MD5: 9a15084eb9eb4ffd00146dfcf3c4008f
SHA1: 2959a7f90c7b2c7c86609ba85cb8eae2a65a51e6
File Size: 3.54 MB, 3540015 bytes
MD5: fb0141ecf6b62e71a45fc75ca69be347
SHA1: 49d88c691e7867cdd61fab989e02310c4ab62702
SHA256: 149687A2F20AD59AC2C2651420DCE3839CAA2E1AEDC90A57E61AF4213702AE2A
File Size: 9.23 MB, 9234766 bytes
MD5: 1fbf230c5bce0ab8085e276dd94f7577
SHA1: 0c886160485f1a5303b6deb27c6582dfac952905
SHA256: 7D1DC18109E1A059797B2806FA8F9959E126C4457FE5DA44731C26FD3C08F202
File Size: 9.52 MB, 9518939 bytes
Show More
MD5: bc0a2ce9318e14d93b9a7a9f3b6c7372
SHA1: c88d59df33be86dfa2dc8ea6a0a2c11d80270468
SHA256: A599403A3FAC9932D479CA70B4D5B628F70799A4B600D68E1F60321E2223A883
File Size: 6.20 MB, 6199825 bytes
MD5: 54255a3e231859b468234aba7e0757af
SHA1: e1c69832f7c6d1de0a824b5246983f5eee316998
SHA256: D9C5C5206B2A6CF8D92F3F558976D0091246DBD4FADB8F13FEF83A831112DD8D
File Size: 1.63 MB, 1627364 bytes
MD5: eb20d2c6a4b19a50bbb7b079ad95efad
SHA1: a8afcadbfee46db4225d1dce4c64098fb1e015ae
SHA256: 34C7189181CF76D40AE8CBB6CC2C6F2E08A1547B74D0B4E043AB072A0185F9AE
File Size: 7.90 MB, 7898226 bytes
MD5: 8a97560062c20d38ddb4cbda4142f68c
SHA1: 59764e48b79e7fece65872377657816adc608ef5
SHA256: 9E3F8A9CA23699C3F753402BD56751704327A7E78BE10FAACFF75CF894FD2E85
File Size: 8.03 MB, 8033590 bytes
MD5: f3261e38c89703748cd5258cf10df168
SHA1: 57440ae0bd947eb14fe614ecb237f91bd9200b28
SHA256: 963AE7961D7AE222B5F4BECEED9B8EAECB36E086916E8E6C7A5FF26874E13DFA
File Size: 3.62 MB, 3615273 bytes
MD5: e62ea53bf9635262ff4406482b132cac
SHA1: 0027aed833fc7ec9aacc3cac8e9199da22bf5b56
SHA256: 13614BDAD2B7435A6CC077EC0AA69D14945572D5AC3204EA28072BB201BD6157
File Size: 8.09 MB, 8086689 bytes
MD5: 2814aba6ff6bb852fd6b89a495d4c94f
SHA1: 15f5332daab5ae5cc9cab14e78ae07cabe57586e
SHA256: A88661371C8E9DD2946AB25DA5DD0189C08BF636D4B06FD85DCE9097B0024EEF
File Size: 9.55 MB, 9550710 bytes
MD5: 1028652bc4026c96aa16f8c0a6318c81
SHA1: 4e21fa8f6909a791dd1615bd8f0ec93976232e41
SHA256: 0601E58FF97191BB3BB806AC9904387DA4386F95B94DEBF9290B1ECCA2D1DC81
File Size: 2.05 MB, 2052709 bytes
MD5: db564d570ad3e2adad26ec96fb576cd7
SHA1: db50292ab16ddf6f2d8b5d75715cf3372da675ab
SHA256: 0FEE4C54A7C8BA1EAD13557D2E3E4D843223A4CC3761B37F846BBF77C207F719
File Size: 7.25 MB, 7248396 bytes
MD5: a059dae7138cfc329f419c7017690e1f
SHA1: 264d3dd7125f698e515063222376764a5fb1b9b2
SHA256: FBF21A277828DAF1CC99E9A511EF5BA475EE4C451BF5B92CFF9E26A4A9CE6708
File Size: 1.15 MB, 1145879 bytes
MD5: cd07d69b7fbf22172a95ab7b977f22c1
SHA1: 138fd901e1707475042aa86c265aefbad3e2da40
SHA256: 72D54375A6B3C5FBC0645827B538B30E51E59B1233C6F9BCC3195B4449F8DBCA
File Size: 8.60 MB, 8599960 bytes
MD5: c0c4e9d7ec80ea7cd730043a2446aaed
SHA1: a4a6bc7214e41ec51104cc317dd9dd354df2461d
SHA256: D2FDC0799A37CC6ED60D800FC7256F087B5761C4BC1E50173BEEFBE23A04DAF3
File Size: 8.22 MB, 8220346 bytes
MD5: a2d45568c6c00880a60f6708055c0d4f
SHA1: 0768e14b634eb55197dfda4191c3e443d0cfe22f
SHA256: 300CEAB28928D4273B0E669C935894EB3B4C077ABF74735707F71DAF2E70ED38
File Size: 8.51 MB, 8506832 bytes
MD5: 8f20af2f8110c14d8080f34c30127d61
SHA1: 3e1afd2c8941dbaffc961793449fcb0b2cf113d0
SHA256: 514C350CB2179C27152760D8FB0A2F1A6177681ABDC1C81562E2146F79417D39
File Size: 2.83 MB, 2833091 bytes
MD5: cfab74bb4340d0abcc0f4b364e7d7718
SHA1: bd0d98935097614772279cc6066abfa84ff0ca8e
SHA256: 965190D6A66AFC78480C942FAE8E55C4B5DF86572C43A0F5F61B014B3AEA10A9
File Size: 2.19 MB, 2194409 bytes
MD5: a2cd35080f268e359a28e6e20621dbed
SHA1: 97c8f22533fda6b6a181e90cf51f25046bf0aa64
SHA256: 52EBB8FA7A4B27296CB9B8C5B968A1C4524E26686088FCA618409FFE88052644
File Size: 9.70 MB, 9701923 bytes
MD5: d27a67c71e880ea049d7c27a86f407f4
SHA1: 4e5af2db0b5ffc0dcafaf2052f1b895c9e4e7fd2
SHA256: 7FFE7092086224E1B4068B906D97F47CC0E3379762ABCBA576ADF27DAD532DD7
File Size: 5.65 MB, 5647265 bytes
MD5: 4f16ef46e46525424cc27bc938cccf51
SHA1: dd8b4c694de2a4b4336f56b5236c13f1c0a76665
SHA256: 3DEAFAB02E7FFB9D1EE3AA69548488566020C34A6F7AFF2EDD53CDCB7536C116
File Size: 8.39 MB, 8388608 bytes
MD5: d4e5e3238c48e50b56d3c94efb8e53b4
SHA1: 3fb2084bc33d42e3d8f0ccea4c3d3e40442125df
SHA256: 015133DA6B07474A5A7AC52C91030357067E73CC89A35BDA100E2173EF5CF53D
File Size: 9.97 MB, 9969554 bytes
MD5: 47b7c9283bbbaa35d46dacd8375e2bcd
SHA1: b4b01a4f2c711905799e7fcab53b678a27251342
SHA256: BDECCE6689F9586EBD79A4C1F06A65BC4A6E9C6F21CF1C196C74DFCD52C25B0E
File Size: 6.76 MB, 6756363 bytes
MD5: 162d06858637a239246335be5515a8a4
SHA1: bba25c305414283b4fd4924da140bf6d3a278660
SHA256: 013BE4C37FA64B48CB8300127CFD134419B94F3FC47F942709979266FE1387F4
File Size: 5.07 MB, 5068935 bytes
MD5: 8ba00a02e58a34688aafe8c7a5b15e48
SHA1: 596703fdcba0d84961c0376c2ac7364a3b41189e
SHA256: 12DD7C9BF94ACDEF80A4104A177AD426E68E3389189A5BCD7BCD3E34B33FCFD5
File Size: 8.05 MB, 8054465 bytes
MD5: 993d1f15ae1a627610d1080dd2d2b3f1
SHA1: 311cdef5917b43e81f7d86095b0ced274001f1e0
SHA256: AB706C8AAEFC491D69E7E2E59E414445F6B37C1FCE5341D7114D128D594FCCBF
File Size: 3.01 MB, 3012728 bytes
MD5: d1fe1dcdfefadd82fdefee50f3faad79
SHA1: 3ff382c6375c76eace843e8a6c9aa72732fc482d
SHA256: 3E98FCFE8675D865664B75D5933B1DCB731080C07EDC7B9E6E22E7B2124E3EFE
File Size: 4.43 MB, 4433438 bytes
MD5: dc6f5437199c5fbc1e290a8ffd843e7f
SHA1: a941c573e893d752087e057946e971c9727e3d85
SHA256: 1122B778A1DBE75A8C597DCA475B3A84966B6D46773F7DB895292D37A7A1421A
File Size: 6.13 MB, 6129175 bytes
MD5: e0e16d1d9df3213facf7332abb90e465
SHA1: 35ea86addc3a52770796ab90ab3975f7b168c335
SHA256: B8AE89C22EA73D0734576228DC134FC9CD2D842D1896FF7A1C1AEC0BB32CC14A
File Size: 8.29 MB, 8285180 bytes
MD5: 6f12b98424d71b45ea7cf66055aaee3b
SHA1: 64163156c02fff574ecc46de262624fa65318639
SHA256: 58FA72EF5986035AE2459B359CF37733EF85925ED7CFCDA9DD36AF2F1FB9A062
File Size: 8.29 MB, 8285305 bytes
MD5: 1d178888d2acf83259e713da217002ed
SHA1: cf8aa12cc16188f545e08f8879d4bf5967f706b1
SHA256: F8994EF27B825F2B42BC8ABE440009175B52AFC3AADEE9A58F5F9A0AA7D1A237
File Size: 8.56 MB, 8558556 bytes
MD5: 9117919c2e48298b89f0dc2c923191fc
SHA1: 53341bfd5fe23e5decbe94f248ab8aa7494dc210
SHA256: 7F96D038F721A4751354A263D4B60B0FFBC4CB5DDF8A48537D6FCC5366332327
File Size: 6.10 MB, 6099859 bytes
MD5: 79f8a1ae93891eb3284ffbbe4c420031
SHA1: fcdd761b4abb0c6092978fb50a70fe9c87b3485a
SHA256: C9EF7BA913FE7ED60BD9B266604833E6588709FE32CC15978CF8ED24CCFDC270
File Size: 9.06 MB, 9059222 bytes
MD5: a69e1bbe0974f168ef318bc8fdce162c
SHA1: 9662e07a6277e324a64f882a1093100db7432bb1
SHA256: 91145E61F62F37DBC8E6CBF5210AAC65EEB0996C0856BDABD4897C52326356CF
File Size: 9.88 MB, 9880208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 64-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • GGQ Company Inc.
  • 睿诚和创自动化科技有限公司
File Description
  • Analysis Engine
  • 音频测试工具
File Version
  • 4.3.3.218
  • 1.1.0.1
Internal Name Analysis Engine
Legal Copyright
  • Copyright 2023 GGQ Company Inc. All rights reserved.
  • 睿诚和创自动化科技有限公司版权所有
Original Filename analysis engine.exe
Product Name
  • Analysis Engine
  • AudioAnalysisTestSystem.exe
Product Version
  • 4.3.3
  • 1.1.0

File Traits

  • big overlay
  • GetConsoleWindow
  • HighEntropy
  • No Version Info
  • Py-installer
  • x64
  • zlib (In Overlay)
  • zlib overlay

Block Information

Total Blocks: 878
Potentially Malicious Blocks: 0
Whitelisted Blocks: 878
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • CobaltStrike.XAA
  • Downloader.Agent.N

Files Modified

File Attributes
c:\users\user\appdata\local\temp\_mei100362\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei100362\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\libffi-8.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei101882\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-fibers-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-stdio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-time-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\api-ms-win-crt-utility-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\base_library.zip Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\libcrypto-3.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\python312.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\select.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\ucrtbase.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\unicodedata.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10682\vcruntime140.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_asyncio.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_bz2.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_ctypes.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_decimal.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_hashlib.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_lzma.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_multiprocessing.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_overlapped.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_queue.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_socket.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_ssl.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\_uuid.pyd Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-console-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-datetime-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-debug-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-errorhandling-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-fibers-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-fibers-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-file-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-file-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-file-l2-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-handle-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-interlocked-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-kernel32-legacy-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-libraryloader-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-localization-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-memory-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-namedpipe-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-processenvironment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-processthreads-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-processthreads-l1-1-1.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-profile-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-rtlsupport-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-string-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-synch-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-synch-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-sysinfo-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-sysinfo-l1-2-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-timezone-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-core-util-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-conio-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-convert-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-environment-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-filesystem-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-heap-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-locale-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-math-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-process-l1-1-0.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\_mei10842\api-ms-win-crt-runtime-l1-1-0.dll Generic Write,Read Attributes

9209 additional files are not displayed above.

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcConnectPort
  • ntdll.dll!NtAlpcQueryInformation
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDeviceIoControlFile
  • ntdll.dll!NtDuplicateObject
Show More
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenDirectoryObject
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenThreadToken
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDirectoryFileEx
  • ntdll.dll!NtQueryFullAttributesFile
  • ntdll.dll!NtQueryInformationFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetTimer2
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • UNKNOWN
  • win32u.dll!NtUserBuildHwndList
  • win32u.dll!NtUserCallTwoParam
  • win32u.dll!NtUserDestroyWindow
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetProp
  • win32u.dll!NtUserGetThreadState
  • win32u.dll!NtUserMsgWaitForMultipleObjectsEx
  • win32u.dll!NtUserPeekMessage
  • win32u.dll!NtUserRegisterWindowMessage
  • win32u.dll!NtUserRemoveProp
  • win32u.dll!NtUserSetWindowFNID
  • win32u.dll!NtUserSetWindowLongPtr
  • win32u.dll!NtUserShowWindow
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

c:\users\user\downloads\ee9e15fe659d302c2ab6791570b6abb34b886259_0009806719.exe "c:\users\user\downloads\ee9e15fe659d302c2ab6791570b6abb34b886259_0009806719.exe"
c:\users\user\downloads\7626f7d00368bcb967ec00582900c4b0412e9223_0008054268.exe "c:\users\user\downloads\7626f7d00368bcb967ec00582900c4b0412e9223_0008054268.exe"
c:\users\user\downloads\49d88c691e7867cdd61fab989e02310c4ab62702_0009234766 "c:\users\user\downloads\49d88c691e7867cdd61fab989e02310c4ab62702_0009234766"
c:\users\user\downloads\0c886160485f1a5303b6deb27c6582dfac952905_0009518939 "c:\users\user\downloads\0c886160485f1a5303b6deb27c6582dfac952905_0009518939"
c:\users\user\downloads\c88d59df33be86dfa2dc8ea6a0a2c11d80270468_0006199825 "c:\users\user\downloads\c88d59df33be86dfa2dc8ea6a0a2c11d80270468_0006199825"
Show More
c:\users\user\downloads\59764e48b79e7fece65872377657816adc608ef5_0008033590 "c:\users\user\downloads\59764e48b79e7fece65872377657816adc608ef5_0008033590"
c:\users\user\downloads\0027aed833fc7ec9aacc3cac8e9199da22bf5b56_0008086689 "c:\users\user\downloads\0027aed833fc7ec9aacc3cac8e9199da22bf5b56_0008086689"
c:\users\user\downloads\15f5332daab5ae5cc9cab14e78ae07cabe57586e_0009550710 "c:\users\user\downloads\15f5332daab5ae5cc9cab14e78ae07cabe57586e_0009550710"
c:\users\user\downloads\db50292ab16ddf6f2d8b5d75715cf3372da675ab_0007248396 "c:\users\user\downloads\db50292ab16ddf6f2d8b5d75715cf3372da675ab_0007248396"
c:\users\user\downloads\a4a6bc7214e41ec51104cc317dd9dd354df2461d_0008220346 "c:\users\user\downloads\a4a6bc7214e41ec51104cc317dd9dd354df2461d_0008220346"
c:\users\user\downloads\97c8f22533fda6b6a181e90cf51f25046bf0aa64_0009701923 "c:\users\user\downloads\97c8f22533fda6b6a181e90cf51f25046bf0aa64_0009701923"
c:\users\user\downloads\4e5af2db0b5ffc0dcafaf2052f1b895c9e4e7fd2_0005647265 "c:\users\user\downloads\4e5af2db0b5ffc0dcafaf2052f1b895c9e4e7fd2_0005647265"
c:\users\user\downloads\3fb2084bc33d42e3d8f0ccea4c3d3e40442125df_0009969554 "c:\users\user\downloads\3fb2084bc33d42e3d8f0ccea4c3d3e40442125df_0009969554"
c:\users\user\downloads\b4b01a4f2c711905799e7fcab53b678a27251342_0006756363 "c:\users\user\downloads\b4b01a4f2c711905799e7fcab53b678a27251342_0006756363"
c:\users\user\downloads\596703fdcba0d84961c0376c2ac7364a3b41189e_0008054465 "c:\users\user\downloads\596703fdcba0d84961c0376c2ac7364a3b41189e_0008054465"
c:\users\user\downloads\a941c573e893d752087e057946e971c9727e3d85_0006129175 "c:\users\user\downloads\a941c573e893d752087e057946e971c9727e3d85_0006129175"
c:\users\user\downloads\35ea86addc3a52770796ab90ab3975f7b168c335_0008285180 "c:\users\user\downloads\35ea86addc3a52770796ab90ab3975f7b168c335_0008285180"
c:\users\user\downloads\64163156c02fff574ecc46de262624fa65318639_0008285305 "c:\users\user\downloads\64163156c02fff574ecc46de262624fa65318639_0008285305"
c:\users\user\downloads\cf8aa12cc16188f545e08f8879d4bf5967f706b1_0008558556 "c:\users\user\downloads\cf8aa12cc16188f545e08f8879d4bf5967f706b1_0008558556"
c:\users\user\downloads\53341bfd5fe23e5decbe94f248ab8aa7494dc210_0006099859 "c:\users\user\downloads\53341bfd5fe23e5decbe94f248ab8aa7494dc210_0006099859"
c:\users\user\downloads\fcdd761b4abb0c6092978fb50a70fe9c87b3485a_0009059222 "c:\users\user\downloads\fcdd761b4abb0c6092978fb50a70fe9c87b3485a_0009059222"
c:\users\user\downloads\9662e07a6277e324a64f882a1093100db7432bb1_0009880208 "c:\users\user\downloads\9662e07a6277e324a64f882a1093100db7432bb1_0009880208"

Related Posts

Trending

Most Viewed

Loading...