FunctionFlow
udurrani
Process | Func | Param |
---|---|---|
kara_sample.exe | Load Image | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | Load Image | C:\Windows\System32\ntdll.dll |
kara_sample.exe | CreateFile | C:\Windows\Prefetch\FF.EXE-AB8E7EC6.pf |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mscoree.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mscoree.dll |
kara_sample.exe | Load Image | C:\Windows\System32\mscoree.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | Load Image | C:\Windows\System32\kernel32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\KernelBase.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions\(Default) |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Srp\GP\DLL |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Srp\GP\DLL |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SESSION MANAGER\SafeDllSearchMode |
kara_sample.exe | Load Image | C:\Windows\System32\advapi32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\msvcrt.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sechost.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sechost.dll |
kara_sample.exe | Load Image | C:\Windows\System32\sechost.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rpcrt4.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\Policy\ |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\v4.0 |
kara_sample.exe | CreateFile | C:\Windows\System32\MSCOREE.DLL.local |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | QueryDirectory | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | QueryDirectory | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | Load Image | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\CLRLoadLogDir |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\System32\MSCOREE.DLL.local |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\InstallRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64 |
kara_sample.exe | QueryDirectory | C:\Windows\Microsoft.NET\Framework64\* |
kara_sample.exe | QueryDirectory | C:\Windows\Microsoft.NET\Framework64 |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\clr.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\clr.dll |
kara_sample.exe | QueryDirectory | C:\Windows\Microsoft.NET\Framework64 |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | Load Image | C:\Windows\System32\shlwapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\gdi32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\user32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\lpk.dll |
kara_sample.exe | Load Image | C:\Windows\System32\usp10.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\imm32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\imm32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\msctf.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Error Message Instrument\ |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Error Message Instrument |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Compatibility32 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32\ff |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Compatibility32 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\IME Compatibility |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\LoadAppInit_DLLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.config |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\OnlyUseLatestCLR |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\Standards |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\standards |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\standards\v2.0.50727 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\standards |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NoClientChecks |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | Load Image | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKCU\Control Panel\Desktop\MuiCached\MachineLanguageConfiguration |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\MUI\Settings |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Control Panel\Desktop |
kara_sample.exe | RegOpenKey | HKCU\Control Panel\Desktop\LanguageConfiguration |
kara_sample.exe | RegEnumValue | HKCU\Control Panel\Desktop\LanguageConfiguration |
kara_sample.exe | RegCloseKey | HKCU\Control Panel\Desktop\LanguageConfiguration |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\MUI\Settings |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Control Panel\Desktop |
kara_sample.exe | RegOpenKey | HKCU\Control Panel\Desktop |
kara_sample.exe | RegQueryValue | HKCU\Control Panel\Desktop\PreferredUILanguages |
kara_sample.exe | RegCloseKey | HKCU\Control Panel\Desktop |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\MUI\Settings |
kara_sample.exe | RegOpenKey | HKCU\Control Panel\Desktop\MuiCached |
kara_sample.exe | RegQueryValue | HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages |
kara_sample.exe | RegQueryValue | HKCU\Control Panel\Desktop\MuiCached\MachinePreferredUILanguages |
kara_sample.exe | RegCloseKey | HKCU\Control Panel\Desktop\MuiCached |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | Load Image | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | ReadFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | QueryDirectory | C:\Windows |
kara_sample.exe | CreateFile | C:\Windows |
kara_sample.exe | QueryDirectory | C:\Windows\WinSxS |
kara_sample.exe | CloseFile | C:\Windows |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | QueryDirectory | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\MSVCR80.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\GCStressStart |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\GCStressStart |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\GCStressStartAtJit |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\DisableConfigCache |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\WMI\Security\e13c0d23-ccbc-4e12-931b-d9cc2eee27e4 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\WMI\Security\cc2bcbba-16b6-4cf3-8990-d74c2e8af500 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\fusion.localgac |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\CacheLocation |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Fusion |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\EnableLog |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\LoggingLevel |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\ForceLog |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\LogFailures |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\VersioningLog |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\LogResourceBinds |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\DisableMSIPeek |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NoClientChecks |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\LocalIntranet |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | Load Image | C:\Windows\System32\shell32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | Load Image | C:\Windows\System32\ole32.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorUseSystemHeap |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\PageAllocatorSystemHeapIsPrivate |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\OLE\Tracing |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en-US |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en-US |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | CreateFile | C:\Windows\Globalization\Sorting\SortDefault.nls |
kara_sample.exe | CreateFileMapping | C:\Windows\Globalization\Sorting\SortDefault.nls |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Globalization\Sorting\SortDefault.nls |
kara_sample.exe | CreateFileMapping | C:\Windows\Globalization\Sorting\SortDefault.nls |
kara_sample.exe | CloseFile | C:\Windows\Globalization\Sorting\SortDefault.nls |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Windows\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173} |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\profapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\profapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\profapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\profapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KnownFolderSettings |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\v2.0.50727\Security\Policy |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\indexbb.dat |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\indexbb |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\indexbb\NIUsageMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\indexbb\ILUsageMask |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\indexbb |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\181938c6\7950e2c5\1 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7950e2c5\59500bd9\1 |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Fusion\GACChangeNotification\Default |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\mscorlib |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryDirectory | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\ole32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rpcss.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rpcss.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rpcss.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\CRYPTBASE.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | Load Image | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | Load Image | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Temporary Internet Files |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Temporary Internet Files |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Temporary Internet Files |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ff.config |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\LatestIndex |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\228f3c2a\1c36aa2a |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryDirectory | C:\Users\xxx\Desktop\ff.INI |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\l_intl.nls |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\l_intl.nls |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\l_intl.nls |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\l_intl.nls |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\l_intl.nls |
kara_sample.exe | CloseFile | C:\Windows\System32\l_intl.nls |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\StrongName |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | Load Image | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\CseOn |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\TailCallOpt |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\PInvokeInline |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\PInvokeCalliOpt |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\NewGCCalc |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\TURNOFFDEBUGINFO |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\DisableHotCold |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\internal\jit\Perf |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest |
kara_sample.exe | CreateFile | C:\Windows\assembly\pubpol4.dat |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index4 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC\PublisherPolicy.tme |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Windows.Forms__b77a5c561934e089 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\61e7e666\c991064\b |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\475dce40\54de69db\4 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\19ab8d57\28384114\6 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2dd6ac50\163e1f5e\9 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\424bd4d8\380df06d\5 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\41c04c7e\7f3b6ac4\11 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3ced59c5\a32f83e\d |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\c991064\369d9902\a |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\MVID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\30bc7c4f\3f50fe4f\7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\3f50fe4f\15719c78\7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\MVID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\3cca06a0\6dc7d4c0\c |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\6dc7d4c0\7a2df6f5\f |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Windows.Forms |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Drawing__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Drawing |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System__b77a5c561934e089 |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Xml__b77a5c561934e089 |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Xml |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Deployment__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Deployment |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Runtime.Serialization.Formatters.Soap |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.Accessibility__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Accessibility |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Security__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Security |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | CreateFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\tzres.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\tzres.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\Windows Error Reporting\WMR |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR\Disable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\WMR |
kara_sample.exe | CreateFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\tzres.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\tzres.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\tzres.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Rpc |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Rpc\MaxRpcSize |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Rpc |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\OOBEInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\Rpc |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows |
kara_sample.exe | CreateFile | C:\Windows\Globalization\en-us.nlp |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\CRYPTSP.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | Load Image | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SESSION MANAGER\SafeProcessSearchMode |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Policies\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\DESHashSessionKeyBackward |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\DESHashSessionKeyBackward |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Management__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\5a8de2c3\2b1a4e4\49 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\73843e06\204871ca\16 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\141dfd70\6b79efab\4d |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\2b1a4e4\77bc637d\4e |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Management |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.8.0.Microsoft.JScript__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\Microsoft.JScript |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Configuration.Install__b03f5f7f11d50a3a |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Configuration.Install |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AppID\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKCR\AppID\kara_sample.exe |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AppID\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKCR\AppID\kara_sample.exe |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\OLE\AppCompat |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE\AppCompat |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\DefaultAccessPermission |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\EveryoneIncludesAnonymous |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{00000134-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Rpc\Extensions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Rpc\Extensions |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Rpc\Extensions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Rpc\Extensions |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\RpcRtRemote.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | Load Image | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\BFE |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\BFE |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\BFE |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\59245B46 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows\DisabledSessions\ |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows\DisabledSessions\ |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\uxtheme.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.3.5.System.Core__b77a5c561934e089 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\7ac727df\7b5311d7\29 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\7b5311d7\281408aa\29 |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Core |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089 |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089\System.Core.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Core\3.5.0.0__b77a5c561934e089 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\ComputerName |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\ComputerName |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName\ComputerName |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\OOBEInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\ComputerName |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\SspiCli.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sspicli.dll |
kara_sample.exe | Load Image | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\shfolder.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\shfolder.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\shfolder.dll |
kara_sample.exe | Load Image | C:\Windows\System32\shfolder.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\DbgJITDebugLaunchSetting |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\.NETFramework\DbgManagedDebugger |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\{108e252d-64b7-4f31-9d46-50e0d4426fa3}.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\{108e252d-64b7-4f31-9d46-50e0d4426fa3}\{108e252d-64b7-4f31-9d46-50e0d4426fa3}.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\{108e252d-64b7-4f31-9d46-50e0d4426fa3}.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\{108e252d-64b7-4f31-9d46-50e0d4426fa3}\{108e252d-64b7-4f31-9d46-50e0d4426fa3}.exe |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | Load Image | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Culture.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\en-US\mscorrc.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\en-US\mscorrc.dll.DLL |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\en\mscorrc.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\en\mscorrc.dll.DLL |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024\Name |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\DESHashSessionKeyBackward |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001\Name |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 001 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.0.0.{108e252d-64b7-4f31-9d46-50e0d4426fa3}__3e56350693f7355e |
kara_sample.exe | CreateFile | C:\Windows\assembly |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly |
kara_sample.exe | CloseFile | C:\Windows\assembly |
kara_sample.exe | CreateFile | C:\Windows\assembly\Desktop.ini |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\Desktop.ini |
kara_sample.exe | CloseFile | C:\Windows\assembly\Desktop.ini |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\{108e252d-64b7-4f31-9d46-50e0d4426fa3}\0.0.0.0__3e56350693f7355e |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Gdiplus.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4 |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4 |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4 |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4 |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | Load Image | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | RegOpenKey | HKLM\Hardware\DeviceMap\VIDEO |
kara_sample.exe | RegQueryValue | HKLM\HARDWARE\DEVICEMAP\VIDEO\MaxObjectNumber |
kara_sample.exe | RegCloseKey | HKLM\HARDWARE\DEVICEMAP\VIDEO |
kara_sample.exe | RegOpenKey | HKLM\Hardware\DeviceMap\Video |
kara_sample.exe | RegQueryValue | HKLM\HARDWARE\DEVICEMAP\VIDEO\\Device\Video4 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\CONTROL\VIDEO\{4E31E370-9A50-48BF-B9AB-BD984A60A5AD}\0000 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\CONTROL\VIDEO\{4E31E370-9A50-48BF-B9AB-BD984A60A5AD}\0000 |
kara_sample.exe | RegCloseKey | HKLM\HARDWARE\DEVICEMAP\VIDEO |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000\PruningMode |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\CLASS\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78\HardwareID |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78\HardwareID |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Enum\PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&18d45aa6&0&78 |
kara_sample.exe | RegOpenKey | HKLM\Hardware\DeviceMap\Video |
kara_sample.exe | RegQueryValue | HKLM\HARDWARE\DEVICEMAP\VIDEO\\Device\Video4 |
kara_sample.exe | RegCloseKey | HKLM\HARDWARE\DEVICEMAP\VIDEO |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\GDIPlus |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\GDIPlus\FontCachePath |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\GDIPlus |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | CreateFile | C:\Windows\Fonts\ahronbd.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\ahronbd.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\ahronbd.ttf |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\tahoma.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\malgun.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\micross.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | CreateFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\segoeui.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msjh.ttf |
kara_sample.exe | CreateFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | CloseFile | C:\Windows\Fonts\msyh.ttf |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegOpenKey | HKCU\EUDC\1252 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Locale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Locale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Language Groups |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\Language Groups |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\Locale\00000409 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\Language Groups\1 |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\dwmapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0 |
kara_sample.exe | CreateFile | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | ReadFile | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | CreateFileMapping | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Segoe UI |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\COM3 |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\COM3 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\COM3\Com+Enabled |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\COM3 |
kara_sample.exe | Load Image | C:\Windows\System32\clbcatq.dll |
kara_sample.exe | Load Image | C:\Windows\System32\oleaut32.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\OLEAUT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\OLEAUT |
kara_sample.exe | CreateFile | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | CreateFileMapping | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | CreateFileMapping | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\OLE |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\MaxSxSHashCount |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\Server |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | Load Image | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA} |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wbemcomn.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | Load Image | C:\Windows\System32\ws2_32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\nsi.dll |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\Logs |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbem\Logs |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\Logs |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\WBEM |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\wminet_utils.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\oleaut32.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Ole |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\OLE |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale\en |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\CustomLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale\en |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\ExtendedLocale |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wbem\NTDSAPI.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\ProcessID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\ContextLimit |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\ObjectLimit |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\IdentifierLimit |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\rpcrt4.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\COM3 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\COM3\FinalizerActivityBypass |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\COM3 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{027947E1-D731-11CE-A357-000000000001} |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | RegQueryKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | RegOpenKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegQueryValue | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default) |
kara_sample.exe | RegCloseKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
kara_sample.exe | RegCloseKey | HKCR\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\OLEAUT32.dll |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
kara_sample.exe | CreateFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CloseFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wshom.ocx |
kara_sample.exe | Load Image | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CloseFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mpr.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mpr.dll |
kara_sample.exe | Load Image | C:\Windows\System32\mpr.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\scrrun.dll |
kara_sample.exe | Load Image | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\version.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\version.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\version.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\version.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\version.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\version.dll |
kara_sample.exe | Load Image | C:\Windows\System32\version.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\version.dll |
kara_sample.exe | RegOpenKey | HKLM\system\CurrentControlSet\control\NetworkProvider\HwOrder |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\control\NetworkProvider\HwOrder |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID\(Default) |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\ProgID |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{00021401-0000-0000-C000-000000000046} |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InProcServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D} |
kara_sample.exe | CreateFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\propsys.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\propsys.dll |
kara_sample.exe | Load Image | C:\Windows\System32\propsys.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Caches |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Caches\cversions.1.db |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Caches |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Caches\cversions.1.db |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk\desktop.ini |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk\desktop.ini |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\SXS.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sxs.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\sxs.dll |
kara_sample.exe | Load Image | C:\Windows\System32\sxs.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib |
kara_sample.exe | RegOpenKey | HKCR\TypeLib |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\TypeLib |
kara_sample.exe | RegQueryKey | HKCR\TypeLib |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegQueryKey | HKCR\TypeLib |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\409 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\409 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\9 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\9 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegOpenKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegQueryKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | RegQueryValue | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64\(Default) |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64 |
kara_sample.exe | CreateFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wshom.ocx |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wshom.ocx |
kara_sample.exe | ReadFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0 |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0 |
kara_sample.exe | RegCloseKey | HKCR\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B} |
kara_sample.exe | RegCloseKey | HKCR\TypeLib |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\System32\shell32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\shell32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\shell32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe.Local |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6 |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6 |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6 |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6 |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CreateFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | Load Image | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | CreateFile | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | CreateFileMapping | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | CreateFileMapping | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | CloseFile | C:\Windows\WindowsShell.Manifest |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions |
kara_sample.exe | RegOpenKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions |
kara_sample.exe | RegEnumKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegOpenKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryValue | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask |
kara_sample.exe | RegCloseKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegEnumKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegCloseKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Windows\Explorer |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users\desktop.ini |
kara_sample.exe | QueryStandardInformationFile | C:\Users\desktop.ini |
kara_sample.exe | ReadFile | C:\Users\desktop.ini |
kara_sample.exe | QueryBasicInformationFile | C:\Users\desktop.ini |
kara_sample.exe | CloseFile | C:\Users\desktop.ini |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory\CurVer |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory\CurVer |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory |
kara_sample.exe | RegCloseKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory |
kara_sample.exe | RegCloseKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder |
kara_sample.exe | RegOpenKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCR\Folder\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCR\AllFilesystemObjects\ShellEx\IconHandler |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryValue | HKCR\Directory\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder |
kara_sample.exe | RegQueryValue | HKCR\Folder\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCR\Folder\DocObject |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects |
kara_sample.exe | RegQueryValue | HKCR\AllFilesystemObjects\DocObject |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects\DocObject |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCR\AllFilesystemObjects\DocObject |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryValue | HKCR\Directory\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder |
kara_sample.exe | RegQueryValue | HKCR\Folder\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCR\Folder\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects |
kara_sample.exe | RegQueryValue | HKCR\AllFilesystemObjects\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCR\AllFilesystemObjects\BrowseInPlace |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory\Clsid |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCR\Directory\Clsid |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder\Clsid |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCR\Folder\Clsid |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects\Clsid |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCR\AllFilesystemObjects\Clsid |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryValue | HKCR\Directory\IsShortcut |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder |
kara_sample.exe | RegQueryValue | HKCR\Folder\IsShortcut |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects |
kara_sample.exe | RegQueryValue | HKCR\AllFilesystemObjects\IsShortcut |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryValue | HKCR\Directory\AlwaysShowExt |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegQueryKey | HKCR\Directory |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Directory |
kara_sample.exe | RegQueryValue | HKCR\Directory\NeverShowExt |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegQueryKey | HKCR\Folder |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Folder |
kara_sample.exe | RegQueryValue | HKCR\Folder\NeverShowExt |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegQueryKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\AllFilesystemObjects |
kara_sample.exe | RegQueryValue | HKCR\AllFilesystemObjects\NeverShowExt |
kara_sample.exe | RegCloseKey | HKCR\AllFilesystemObjects |
kara_sample.exe | RegCloseKey | HKCR\Folder |
kara_sample.exe | RegCloseKey | HKCR\Directory |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | FileSystemControl | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | FileSystemControl | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | FileSystemControl | C:\Users\xxx\AppData |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | FileSystemControl | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Pictures |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Video |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Desktop |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Documents |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonPictures |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonMusic |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\CommonVideo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Favorites |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{DE92C1C7-837F-4F69-A3BB-86E631204A23} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{374DE290-123F-4565-9164-39C4925E467B} |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{3D644C9B-1FB8-4F30-9B45-F670235F79C0} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Startup |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Programs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Programs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{56784854-C6CB-462B-8169-88E350ACB882} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | FileSystemControl | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | FileSystemControl | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | FileSystemControl | C:\Users\xxx\AppData |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | FileSystemControl | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | FileSystemControl | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | FileSystemControl | C:\Users\xxx\AppData |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\desktop.ini |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\desktop.ini |
kara_sample.exe | ReadFile | C:\Users\xxx\Desktop\desktop.ini |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop\desktop.ini |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\desktop.ini |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE} |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1 |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Notepad.lnk |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\App Paths\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Windows\System32 |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32 |
kara_sample.exe | CloseFile | C:\Windows\System32 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | Load Image | C:\Windows\System32\setupapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\cfgmgr32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\devobj.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Setup |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b6-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b5-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Data |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\bcrypt.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\bcrypt.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | Load Image | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\System |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileBufferedSynchronousIo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\System |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryStreamInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryEaInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | QueryAttributeInformationVolume | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | QueryAttributeInformationVolume | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | SetEndOfFileInformationFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\System |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileChunkSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\System\CopyFileOverlappedCount |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\System |
kara_sample.exe | ReadFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | ReadFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | ReadFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\svchost.exe |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\Progid |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\(Default) |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryValue | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32\ThreadingModel |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandler |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegQueryKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
kara_sample.exe | RegCloseKey | HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM\EnableObjectValidation |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\WBEM\CIMOM |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\159a66b8\424bd4d8\6 |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\ConfigMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\ConfigString |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\MVID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\EvalationData |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\ILDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\NIDependencies |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5\MissingDependencies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\NI\6faf58\19ab8d57\5 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3\DisplayName |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3\Status |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3\Modules |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3\SIG |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3\LastModTime |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64\IL\75638fee\72533f06\3 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.2.0.System.Data.SqlXml__b77a5c561934e089 |
kara_sample.exe | RegQueryValue | "HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default\System.Data.SqlXml |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | Load Image | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | QueryDirectory | C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.INI |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000\mscorwks.dll |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework\Policy\AppPatch\v4.0.30319.00000 |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CloseFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\machine.config |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ff.config |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ff.config |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\InstallationType |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\rasapi32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\rasapi32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\rasman.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasman.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasman.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rasman.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\rtutils.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rtutils.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rtutils.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rtutils.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Tracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\EnableConsoleTracing |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Tracing |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Tracing\ff_RASAPI32 |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Tracing |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Tracing |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Tracing\ff_RASAPI32 |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableFileTracing |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableConsoleTracing |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileTracingMask |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\ConsoleTracingMask |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\MaxFileSize |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableFileTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableConsoleTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\ConsoleTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\MaxFileSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableFileTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableConsoleTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\ConsoleTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\MaxFileSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SQMServiceList |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SQMServiceList |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SQMServiceList\SQMServiceList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\SQMServiceList |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\WinSock_Registry_Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\WinSock_Registry_Version |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog\069FA29A |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AppId_Catalog |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Callout |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Callout |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\00000007 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries64 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000005 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000006 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000007 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000008 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000009 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000010 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000011 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000012 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000013 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000013\PackedCatalogItem |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000013\PackedCatalogItem |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000013 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\00000022 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries64 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000001 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000002 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000003 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000004 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000005 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000006 |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\LibraryPath |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\DisplayString |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\ProviderId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\AddressFamily |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\SupportedNameSpace |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\Enabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\StoresServiceClassInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\ProviderInfo |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007\ProviderInfo |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock2\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Ws2_32NumHandleBuckets |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | CreateFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mswsock.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\mswsock.dll |
kara_sample.exe | Load Image | C:\Windows\System32\mswsock.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Parameters\Transports |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Parameters\Transports |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\Mapping |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\Mapping |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip\WinSock 2.0 Provider ID |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\MinSockaddrLength |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\MaxSockaddrLength |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\UseDelayedAcceptance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\HelperDllName |
kara_sample.exe | CreateFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | Load Image | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Parameters\Transports |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Parameters\Transports |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\Mapping |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock\Mapping |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\Mapping |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\Mapping |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip6 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip6\WinSock 2.0 Provider ID |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers\Tcpip6 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Winsock\Setup Migration\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Winsock |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\MinSockaddrLength |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\MaxSockaddrLength |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\UseDelayedAcceptance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock\HelperDllName |
kara_sample.exe | CreateFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wship6.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\wship6.dll |
kara_sample.exe | Load Image | C:\Windows\System32\wship6.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Winsock |
kara_sample.exe | CreateFile | C:\Windows\Globalization\en.nlp |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\.NET CLR Networking\Performance |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\.NET CLR Networking\Performance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\Library |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\Library |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\IsMultiInstance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\IsMultiInstance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\First Counter |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\First Counter |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\.net clr networking\Performance |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\.net clr networking\Performance |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\CategoryOptions |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\CategoryOptions |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\FileMappingSize |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\FileMappingSize |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\Counter Names |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\Counter Names |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance\Counter Names |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\.NET CLR Networking\Performance |
kara_sample.exe | CreateFile | C:\Windows\System32\en-US\KernelBase.dll.mui |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\en-US\KernelBase.dll.mui |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\System32\en-US\KernelBase.dll.mui |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\en-US\KernelBase.dll.mui |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Tracing\ff_RASMANCS |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Tracing |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Tracing |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\Tracing\ff_RASMANCS |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableFileTracing |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableConsoleTracing |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileTracingMask |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\ConsoleTracingMask |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\MaxFileSize |
kara_sample.exe | RegSetValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableFileTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableConsoleTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\ConsoleTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\MaxFileSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableFileTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\EnableConsoleTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\ConsoleTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\MaxFileSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableFileTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\EnableConsoleTracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\ConsoleTracingMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\MaxFileSize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileDirectory |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS\FileDirectory |
kara_sample.exe | RegOpenKey | HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\winhttp.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\winhttp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\winhttp.dll |
kara_sample.exe | Load Image | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\webio.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\webio.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\webio.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\webio.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\webio.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\webio.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\webio.dll |
kara_sample.exe | Load Image | C:\Windows\System32\webio.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\webio.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\Tracing |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\Tracing\Enabled |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\Tracing |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ShareCredsWithWinHttp |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\DisableBranchCache |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\IPHLPAPI.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | Load Image | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\WINNSI.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\winnsi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\dhcpcsvc6.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | Load Image | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\dhcpcsvc.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | Load Image | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadOverride |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\peerdist.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | Load Image | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\USERENV.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\userenv.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\userenv.dll |
kara_sample.exe | Load Image | C:\Windows\System32\userenv.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\AUTHZ.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\authz.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\authz.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\authz.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\authz.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\authz.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\authz.dll |
kara_sample.exe | Load Image | C:\Windows\System32\authz.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\authz.dll |
kara_sample.exe | QueryNameInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureDll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli\CheckSignatureRoutine |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\LsaExtensionConfig\SspiCli |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SecurityProviders |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SecurityProviders |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SecurityProviders |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\SecurityProviders |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\credssp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\credssp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\credssp.dll |
kara_sample.exe | Load Image | C:\Windows\System32\credssp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Name |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Name |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Comment |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Comment |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Capabilities |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\RpcId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\Type |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll\TokenSize |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\SspiCache\credssp.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles |
kara_sample.exe | RegEnumValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles |
kara_sample.exe | RegEnumValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\SaslProfiles |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\CLASS\{4D36E972-E325-11CE-BFC1-08002BE10318} |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f9-9c-52 |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f9-9c-52\WpadDecision |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f9-9c-52\WpadDecisionTime |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\00-50-56-f9-9c-52 |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\iphlpapi.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\DNSAPI.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DomainNameDevolutionLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AppendToMultiLabelName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenBadTlds |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenUnreachableServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenDefaultServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DynamicServerQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\FilterClusterIp |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\WaitForNameErrorOnAll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseEdns |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsSecureNameQueryFallback |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableDAForAllNetworks |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DirectAccessQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryIpMatching |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseHostsFile |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AddrConfigControl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterPrimaryName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterReverseLookup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableReverseAddressRegistrations |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterWanAdapters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableWanDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationTTL |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateTopLevelDomainZones |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationOverwrite |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheSize |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxNegativeCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AdapterTimeoutLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ServerPriorityTimeLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCachedSockets |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastResponderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderMaxTimeout |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsTest |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\CacheAllCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseNewRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistrationOnly |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DomainNameDevolutionLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AppendToMultiLabelName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenBadTlds |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenUnreachableServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenDefaultServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DynamicServerQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\FilterClusterIp |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\WaitForNameErrorOnAll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseEdns |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsSecureNameQueryFallback |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableDAForAllNetworks |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DirectAccessQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryIpMatching |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseHostsFile |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AddrConfigControl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterPrimaryName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterReverseLookup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableReverseAddressRegistrations |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterWanAdapters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableWanDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationTTL |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateTopLevelDomainZones |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationOverwrite |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheSize |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxNegativeCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AdapterTimeoutLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ServerPriorityTimeLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCachedSockets |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastResponderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderMaxTimeout |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsTest |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\CacheAllCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseNewRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistrationOnly |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\SearchList |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\SearchList |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SQMClient\Windows |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SQMClient\Windows |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SQMClient\Windows |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\NetBT\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\NodeType |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\DhcpNodeType |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\ScopeId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\DhcpScopeId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\EnableProxy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\EnableDns |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\NetBT\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DNS |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UseDomainNameDevolution |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DomainNameDevolutionLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\PrioritizeRecordData |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\AllowUnqualifiedQuery |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AppendToMultiLabelName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenBadTlds |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenUnreachableServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ScreenDefaultServers |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DynamicServerQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\FilterClusterIp |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\WaitForNameErrorOnAll |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseEdns |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsSecureNameQueryFallback |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableDAForAllNetworks |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DirectAccessQueryOrder |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\QueryIpMatching |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseHostsFile |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AddrConfigControl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterPrimaryName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\EnableAdapterDomainNameRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterReverseLookup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableReverseAddressRegistrations |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegisterWanAdapters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DisableWanDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationTTL |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DefaultRegistrationRefreshInterval |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\UpdateSecurityLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UpdateTopLevelDomainZones |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DowncaseSpnCauseApiOwnerIsTooLazy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\RegistrationOverwrite |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheSize |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxNegativeCacheTtl |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\AdapterTimeoutLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ServerPriorityTimeLimit |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MaxCachedSockets |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastResponderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderFlags |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\MulticastSenderMaxTimeout |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsTest |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\CacheAllCompartments |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\UseNewRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\ResolverRegistrationOnly |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Dnscache\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\DnsQuickQueryTimeouts |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\NameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\NameServer |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpNameServer |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d}\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\QueryAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableAdapterDomainName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DisableDynamicUpdate |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableAdapterDomainNameRegistration |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationMaxAddressCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\MaxNumberOfAddressesToRegister |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableMulticast |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1E769E56-995C-49B3-B7EB-B9B9A64D962D} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\SearchList |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\SearchList |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\NetBT\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\NetBT\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\NodeType |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\DhcpNodeType |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\ScopeId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\DhcpScopeId |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\EnableProxy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\NetBT\Parameters\EnableDns |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\NetBT\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\DnsCache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows NT\DnsClient |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSClient |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Dnscache\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\WinSock2\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\WinSock_Registry_Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\WinSock_Registry_Version |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AutodialDLL |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\AutodialDLL |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\rasadhlp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | Load Image | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | Load Image | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62dc3258-3939-4278-aac7-cd61b8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{62DC3258-3939-4278-AAC7-CD61B8601582} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{3D69624E-1454-4A9F-AC55-D984C1A3730B} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b}\Dhcpv6Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{3d69624e-1454-4a9f-ac55-d984c1a3730b} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\EnableDhcp |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegistrationEnabled |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\RegisterAdapterName |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\Domain |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}\DhcpDomain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963} |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip6\Parameters\Interfaces\{846EE342-7039-11DE-9D20-806E6F6E6963} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{156afe5f-3b96-4276-b8e5-1ec5a9df62e0} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{1e769e56-995c-49b3-b7eb-b9b9a64d962d} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegQueryKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{58849258-4e0e-4375-b735-538e76eaf315} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Interfaces |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Linkage |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Linkage\Bind |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Linkage |
kara_sample.exe | TCP Connect | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\security.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\security.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\security.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\security.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\security.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\security.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\security.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\security.dll |
kara_sample.exe | Load Image | C:\Windows\System32\security.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\security.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\SECUR32.DLL |
kara_sample.exe | CreateFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\secur32.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\secur32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\secur32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\schannel.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\schannel.dll |
kara_sample.exe | Load Image | C:\Windows\System32\schannel.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | Load Image | C:\Windows\System32\crypt32.dll |
kara_sample.exe | Load Image | C:\Windows\System32\msasn1.dll |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\crypt32\DebugHeapFlags |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\crypt32 |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel |
kara_sample.exe | RegCreateKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\Schannel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\UserContextLockCount |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\UserContextListCount |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ncrypt.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | Load Image | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\msasn1 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | CreateFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | Load Image | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\Enabled |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Lsa |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Policies\Microsoft\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\crypt32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllDecodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllDecodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CRYPT32.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\crypt32\DiagLevel |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\crypt32\DiagMatchAnyMask |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\ChainEngine\Config |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableMandatoryBasicConstraints |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableCANameConstraints |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\DisableUnsupportedCriticalExtensions |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlCountInCert |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCountPerChain |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxUrlRetrievalByteCount |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalByteCount |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\MaxAIAUrlRetrievalCertCount |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\CryptnetPreFetchTriggerPeriodSeconds |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config\ChainCacheResyncFiletime |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\#16 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv\Ldap |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllOpenStoreProv |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllOpenStoreProv |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\Keys |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\CA\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies |
kara_sample.exe | RegCloseKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\CA\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\CA\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies |
kara_sample.exe | RegCloseKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Disallowed\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPublisher\Safer |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryKeySecurity | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Root\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegCreateKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Root\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies |
kara_sample.exe | RegCloseKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPeople\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\TrustedPeople\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\trust\PhysicalStores |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies |
kara_sample.exe | RegCloseKey | HKCU\Software |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\trust\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\trust\PhysicalStores |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegCreateKey | HKLM\Software\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegCreateKey | HKLM\Software |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegCreateKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\EnterpriseCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryKeySecurity | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\742C3192E607E424EB4549542BE1BBC53E6174E2 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\CTLs |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\GPAPI.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\gpapi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\gpapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\gpapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\System |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\System |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\System |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\System |
kara_sample.exe | RegOpenKey | HKLM\System\Setup |
kara_sample.exe | RegQueryValue | HKLM\SYSTEM\Setup\SystemSetupInProgress |
kara_sample.exe | RegCloseKey | HKLM\SYSTEM\Setup |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\109F1CAED645BB78B3EA2B94C0697C740733031C |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\D559A586669B08F46A30A133F8A9ED3D038E2EA8 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\FEE449EE0E3965A5246F000E87FDE2A065FD89D4 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs\A377D1B1C0538833035211F4083D00FECC414DAB |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA\CTLs |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My |
kara_sample.exe | NotifyChangeDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\637162CC59A3A1E25956FA5FA8F60D2E1C52EAC6 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931\Blob |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates\7D7F4414CCEF168ADF6BF40753B5BECD78375931 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\Certificates |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CRLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople\CTLs |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\p2pcollab.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\p2pcollab.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\p2pcollab.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\qagentrt.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | CloseFile | C:\Windows\System32\QAGENTRT.DLL |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\qagentrt.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\dnsapi.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\system32\dnsapi.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\System32\fveui.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\System32\fveui.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.1!7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\System32\fveui.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7\Name |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings\StringCacheGeneration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\MUI\StringCacheSettings |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Local Settings\MuiCache\b\52C64B7E |
kara_sample.exe | RegSetValue | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\LanguageList |
kara_sample.exe | CreateFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\fveui.dll |
kara_sample.exe | RegQueryValue | "HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E\@%SystemRoot%\System32\fveui.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes\Local Settings\MuiCache\B\52C64B7E |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.67.1.2!7 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\cryptnet.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | Load Image | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | Load Image | C:\Windows\System32\Wldap32.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\LDAP |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\LDAP |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\ldap\LdapClientIntegrity |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\ldap |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\LDAP |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\LDAP |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\ldap\UseOldHostResolutionOrder |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\ldap |
kara_sample.exe | ReadFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\TVO |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\UrlDllGetObjectUrl |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\UrlDllGetObjectUrl |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\SensApi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\SensApi.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\SensApi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\SensApi.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\SystemCertificates\AuthRoot\AutoUpdate |
kara_sample.exe | RegOpenKey | HKLM\SYSTEM\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\crypt32 |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\crypt32\DebugFlags |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\crypt32 |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\SchemeDllRetrieveEncodedObjectW |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\SchemeDllRetrieveEncodedObjectW |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000\ProfileImagePath |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1400670246-2581911933-2921422024-1000 |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | QuerySecurityFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\LocalLow |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\Cabinet.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cabinet.dll |
kara_sample.exe | Load Image | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\DEVRTL.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\devrtl.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\devrtl.dll |
kara_sample.exe | Load Image | C:\Windows\System32\devrtl.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | CreateFile | C:\Windows\inf |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\inf |
kara_sample.exe | CloseFile | C:\Windows\inf |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Setup |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogLevel |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMask |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\LogMaxFileSize |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\CabBD46.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\TarBD56.tmp |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography |
kara_sample.exe | RegSetInfoKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Cryptography\MachineGuid |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\Offload |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\DESHashSessionKeyBackward |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllConvertPublicKeyInfo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllConvertPublicKeyInfo |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllVerifyCertificateChainPolicy |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CertDllVerifyCertificateChainPolicy |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllEncodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.1.1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.11 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.12 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.2 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.3 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumValue | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx\1.2.840.113549.1.9.16.2.4 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllEncodeObjectEx |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\Root\ProtectedRoots |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllVerifyEncodedSignature |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllVerifyEncodedSignature |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Cryptography\OID |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptDllImportPublicKeyInfoEx2 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegQueryKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1\CryptDllImportPublicKeyInfoEx2 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 1 |
kara_sample.exe | RegEnumKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Providers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Cryptography\Configuration |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\ |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libeay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_core-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libevent_extra-2-0-5.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libgcc_s_sjlj-1.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\libssp-0.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\ssleay32.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor-gencert.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll.tmp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll |
kara_sample.exe | SetBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\zlib1.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD.zip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor\torrc |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | SetRenameInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\tor.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor\geoip6 |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data\Tor |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD\Data |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\ai3VD |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | Process Create | C:\windows\system32\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\AppCertDlls |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers |
kara_sample.exe | RegOpenKey | HKCU\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\SafeBoot\Option |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Session Manager\AppCompatibility |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\Windows\AppCompat |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CreateFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\apphelp.dll |
kara_sample.exe | Load Image | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | WriteFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | SetEndOfFileInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Microsoft.vshub.32.exe |
kara_sample.exe | QuerySecurityFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryNameInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | Process Create | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QuerySecurityFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | CreateFileMapping | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | CreateFileMapping | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | QueryStandardInformationFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\Tor\* |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | QueryDirectory | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | ReadFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\ui\SwDRM.dll |
kara_sample.exe | ReadFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | ReadFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | QuerySecurityFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QuerySecurityFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Windows\AppPatch\sysmain.sdb |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CreateFileMapping | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | QueryStandardInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Connect | WIN-TAKV3SQU51G:49174 -> WIN-TAKV3SQU51G:9056 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49174 -> WIN-TAKV3SQU51G:9056 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49174 -> WIN-TAKV3SQU51G:9056 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Hostname |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\Software\Policies\Microsoft\System\DNSclient |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Services\Tcpip\Parameters |
kara_sample.exe | RegQueryValue | HKLM\System\CurrentControlSet\services\Tcpip\Parameters\Domain |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\Tcpip\Parameters |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\3 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\3 |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc} |
kara_sample.exe | RegOpenKey | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc} |
kara_sample.exe | RegQueryKeySecurity | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc} |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc} |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Connect | WIN-TAKV3SQU51G:49175 -> WIN-TAKV3SQU51G:8181 |
kara_sample.exe | TCP Accept | WIN-TAKV3SQU51G:8181 -> WIN-TAKV3SQU51G:49175 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:8181 -> WIN-TAKV3SQU51G:49175 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49175 -> WIN-TAKV3SQU51G:8181 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\mswsock.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | TCP Connect | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49175 -> WIN-TAKV3SQU51G:8181 |
kara_sample.exe | TCP Send | WIN-TAKV3SQU51G:8181 -> WIN-TAKV3SQU51G:49175 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:8181 -> WIN-TAKV3SQU51G:49175 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | TCP Disconnect | WIN-TAKV3SQU51G:49175 -> WIN-TAKV3SQU51G:8181 |
kara_sample.exe | TCP Disconnect | WIN-TAKV3SQU51G:8181 -> WIN-TAKV3SQU51G:49175 |
kara_sample.exe | TCP Receive | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | TCP Disconnect | WIN-TAKV3SQU51G:49176 -> WIN-TAKV3SQU51G:9055 |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryNameInformationFile | C:\Users\xxx\AppData\Local\Temp\Tor\Microsoft.vshub.32.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Microsoft.vshub.32.exe |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\psapi.dll |
kara_sample.exe | Load Image | C:\Windows\System32\psapi.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | QueryNetworkOpenInformationFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | QueryAttributeTagFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | SetDispositionInformationFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\aes |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\shell32.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MaximizeApps |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\EnableShellExecuteHooks |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ReadMe.html |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\ |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume |
kara_sample.exe | RegQueryValue | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963}\Generation |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{f3bda0b2-5f65-11e7-8f16-806e6f6e6963} |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions |
kara_sample.exe | RegOpenKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions |
kara_sample.exe | RegEnumKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegQueryKey | HKCU\Software\Classes |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegOpenKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegOpenKey | HKCU\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegQueryValue | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask |
kara_sample.exe | RegCloseKey | HKCR\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
kara_sample.exe | RegEnumKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | RegCloseKey | HKCR\Drive\shellex\FolderExtensions |
kara_sample.exe | QueryDirectory | C:\Users |
kara_sample.exe | CreateFile | C:\Users |
kara_sample.exe | FileSystemControl | C:\Users |
kara_sample.exe | QueryDirectory | C:\Users\xxx |
kara_sample.exe | CloseFile | C:\Users |
kara_sample.exe | CreateFile | C:\Users\xxx |
kara_sample.exe | FileSystemControl | C:\Users\xxx |
kara_sample.exe | QueryDirectory | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | FileSystemControl | C:\Users\xxx\Desktop |
kara_sample.exe | QueryDirectory | C:\Users\xxx\Desktop\ReadMe.html |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop\ReadMe.html |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | Process Create | C:\windows\system32\cmd.exe |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Users\xxx\Desktop |
kara_sample.exe | QueryBasicInformationFile | C:\Users\xxx\Desktop |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | CreateFileMapping | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | Process Create | C:\windows\system32\cmd.exe |
kara_sample.exe | QuerySecurityFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | QueryBasicInformationFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | RegOpenKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
kara_sample.exe | RegOpenKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\cmd.exe |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide |
kara_sample.exe | CloseFile | C:\Windows\System32\cmd.exe |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
kara_sample.exe | ReadFile | C:\Windows\System32\ole32.dll |
kara_sample.exe | CloseFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\security.config.cch.2960.1029122 |
kara_sample.exe | CreateFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\CONFIG\enterprisesec.config.cch.2960.1029122 |
kara_sample.exe | CreateFile | C:\Users\xxx\AppData\Roaming\Microsoft\CLR Security Config\v2.0.50727.312\64bit\security.config.cch.2960.1029138 |
kara_sample.exe | ReadFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | ReadFile | C:\Windows\System32\clbcatq.dll |
kara_sample.exe | CloseFile | C:\Windows\Registration\R000000000006.clb |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default |
kara_sample.exe | CloseFile | C:\Windows\assembly\pubpol4.dat |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer |
kara_sample.exe | RegOpenKey | HKLM\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize |
kara_sample.exe | RegQueryValue | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize |
kara_sample.exe | QueryNameInformationFile | C:\Users\xxx\Desktop\kara_sample.exe |
kara_sample.exe | QueryNameInformationFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf\msvcr80.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\security.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\user32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\kernel32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\ntdll.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\psapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\WMINet_Utils.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Windows.Forms\2e0044fa7cabadce65fa8964fe2c90dd\System.Windows.Forms.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Xml\1fb1b14199d6aec70df1a0626a3ae5f2\System.Xml.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cabinet.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Configuration\907b2b3dae591e0484acfc0ea63e8caa\System.Configuration.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Core\27ed9d7013e71f31cacdf8cc438386b6\System.Core.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Management\c58314beec308d002d31dd33ff970d5e\System.Management.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System.Drawing\10f1e1ffca16e550af8a8fd7685a48ef\System.Drawing.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\System\247913fa7ae6fcf04ea33d28d24ab611\System.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorjit.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\mscorlib\9a017aa8d51322f18a40f414fa35872d\mscorlib.ni.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorwks.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\mscoree.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rasman.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rasapi32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rasadhlp.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wbem\wmiutils.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wbem\wbemsvc.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wbem\wbemprox.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\ntdsapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wbem\fastprox.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wbemcomn.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\mpr.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\webio.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\winhttp.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\dhcpcsvc.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\dhcpcsvc6.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\FWPUCLNT.DLL |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\winnsi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\IPHLPAPI.DLL |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cryptnet.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\scrrun.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wshom.ocx |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\SensApi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\PeerDist.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rtutils.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\dwmapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4\GdiPlus.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\uxtheme.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\propsys.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6\comctl32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\version.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\WSHTCPIP.DLL |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\shfolder.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\gpapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\userenv.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\devrtl.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\credssp.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\bcryptprimitives.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rsaenh.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\schannel.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\dnsapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\wship6.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\mswsock.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cryptsp.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\bcrypt.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\ncrypt.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\authz.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\secur32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\sspicli.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\apphelp.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cryptbase.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\sxs.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\RpcRtRemote.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\profapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\msasn1.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\devobj.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\crypt32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\KernelBase.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\cfgmgr32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\imm32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\sechost.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\lpk.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\gdi32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\ws2_32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\Wldap32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\rpcrt4.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\clbcatq.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\usp10.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\ole32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\nsi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\msctf.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\shlwapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\advapi32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\shell32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\setupapi.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\oleaut32.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\msvcrt.dll |
kara_sample.exe | QueryNameInformationFile | C:\Windows\System32\apisetschema.dll |
kara_sample.exe | CloseFile | C:\Users\xxx\Desktop |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\Sorting\Versions |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\SESSION MANAGER |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\.NETFramework |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_64 |
kara_sample.exe | CloseFile | C:\Windows\assembly\NativeImages_v2.0.50727_64\indexbb.dat |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlp |
kara_sample.exe | CloseFile | C:\Windows\assembly\GAC_64\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlp |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7600.16385_none_2b4f45e87195fcc4 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\Locale |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\Language Groups |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts |
kara_sample.exe | CloseFile | C:\Windows\Fonts\StaticCache.dat |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | RegCloseKey | HKCU\Software\Classes |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4927_none_88dce9872fb18caf |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\Control\NetworkProvider\HwOrder |
kara_sample.exe | CloseFile | C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_fa645303170382f6 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASAPI32 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9 |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\WinSock2\Parameters\NameSpace_Catalog5 |
kara_sample.exe | CloseFile | C:\Windows\System32\en-US\KernelBase.dll.mui |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Tracing\ff_RASMANCS |
kara_sample.exe | RegCloseKey | HKLM\System\CurrentControlSet\services\crypt32 |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\My |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\Root |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\SystemCertificates\trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates |
kara_sample.exe | RegCloseKey | HKCU\Software\Policies\Microsoft\SystemCertificates |
kara_sample.exe | CloseFile | C:\Users\xxx\AppData\Roaming\Microsoft\SystemCertificates\My |
kara_sample.exe | RegCloseKey | HKCU\Software\Microsoft\Windows NT\CurrentVersion |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags |
kara_sample.exe | RegCloseKey | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options |
kara_sample.exe | TCP Disconnect | WIN-TAKV3SQU51G.localdomain:49164 -> saxatile.torproject.org:https |
kara_sample.exe | TCP Disconnect | WIN-TAKV3SQU51G:49174 -> WIN-TAKV3SQU51G:9056 |