Report #5360 check_circle

  • Creation Date: Nov. 22, 2019, 4:40 p.m.
  • Last Update: Nov. 22, 2019, 4:45 p.m.
  • File: VID001.exe
  • Results:
Binary
DLL
False cancel
Size
2.25MB
trid
94.6% NSIS - Nullsoft Scriptable Install System
3.4% Win32 Executable MS Visual C++
0.7% Win32 Dynamic Link Library
0.5% Win32 Executable
0.2% OS/2 Executable
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
2915b3f8b703eb744fc54c81f4a9c67f
sha1
e10361a11f8a7f232ac3cb2125c1875a0a69a3e4
crc32
0x8aacaf15
sha224
0fa3451ef5ad210266786135b76ae23914f9aba4169f2b2cf801ee46
sha256
9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
sha384
55ad28a6680d1b731ac08a916ee3fe0a28761a1ddb437ce72d5a6fc94e50edd075b7ba7e6292634d113837be7fc2f4a7
sha512
84e53163c255edde6a0f2289b67166ad8c4f3e2b06e92b7d9dd3d8701a58b4c6f6c661be0c9f0777677bcd36de0a7cccc6512d953c4ba12d8b5c6a35617f3816
ssdeep
49152:ytSuw/yQBQIlFZ4n5gcdRVGTZYf0hrSkW6OoXWr0u3r8t9V808b:QnID2n5pViC8hrRW9X78tjIb
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
domain, contentis_base64, screenshot, win_private_profile, url, HasRichSignature, win_files_operation, win_registry, Nullsoft_PiMP_Stub_SFX, HasOverlay, CRC32_poly_Constant, win_token, IsPE32, escalate_priv, IsWindowsGUI, IP, IsPacked

Suspicious
True check_circle

Strings
List
http://nsis.sf.net/NSIS_Error
c.Th
tup.CW
OHPLlK1.BA
8.GS
G.kP
k.Im
p.Mp
cek.Cw
D.Sd
c.Tw
s.pY
d.bg
5.sk
8.AL
MQ.so
f{d.eE{{
2H.Aw`
))r.GA
`A.Bh
Z.Se
y.ST[}
COMCTL32.dll
VERSION.dll
~nsu.tmp
tATP%
5aI:p6
Ohd8&o
%/AiH
Fh>t
fDc7sl}WsXM
S.%8n%\>
0e%A@ee6>
S4%dt,TF
D0<BA%nb
{%=%5Ai
@7}%%
%Eu2n
dH0%E
hH%EC*)
tl?%f
.%%=!
-?'%e
(t)%i
i/%ow
}yt%e
%de)o
%EpA$
i%l%S
O%d\i
<iLh%E
verifying installer: %d%%
%aTau;n
GdT
rl%oi
Software\Microsoft\Windows\CurrentVersion
%cbUTm
%a EA8
installer's author to obtain a new copy.
Installer integrity check has failed. Common causes include
Control Panel\Desktop\ResourceLocale
.DEFAULT\Control Panel\International
[Rename]
SeShutdownPrivilege
>eSsLM
ci.bY~
Y.zgo?
SshWdi
uDSSh
GetProcAddress
ExitProcess
7.Lb'
D.kN:
NullsoftInst
GetDiskFreeSpaceA
CreateProcessA
OpenProcessToken
ShellExecuteA
CoCreateInstance
MoveFileExA
RegDeleteKeyExA
DeleteFileA
SetFileTime
RegSetValueExA
RegCreateKeyExA
CreateDirectoryA
GetModuleHandleA
GetModuleFileNameA
CopyFileA
LoadLibraryA
RemoveDirectoryA
LoadLibraryExA
FreeLibrary
RegEnumKeyA
RegQueryValueExA
FindFirstFileA
CreateFileA
RegDeleteValueA
RegDeleteKeyA
RegOpenKeyExA

Foremost
Matches
0.exe, 93 KB, 62.png, 36 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: True check_circle
Suspicious: http://nsis.sf.net/nsis_error
hasAllowed: False cancel
hasSuspicious: True check_circle

Files
Allowed: ADVAPI32.dll, SHELL32.dll, USER32.dll, KERNEL32.dll, VERSION.dll, COMCTL32.dll, ole32.dll, GDI32.dll
hasFiles: True check_circle
Suspicious: MQ.so, ~nsu.tmp
hasAllowed: True check_circle
hasSuspicious: True check_circle

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 308224
Suspicious: False cancel
Image
Address: 4194304
Suspicious: False cancel
Stack
Stack: 4096
Suspicious: False cancel
Headers
Headers: 1024
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 0
Suspicous: True check_circle

Sections
Allowed: .text, .rdata, .data, .ndata, .rsrc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 4
Suspicious: False cancel
Image
Version: False cancel
Suspicious: 4
Linker
Version: 6.0
Suspicious: False cancel
Subsystem
Version: 4.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 12538
Suspicious: False cancel

Anomalies
Anomalies: The header checksum and the calculated checksum do not match.
hasAnomalies: True check_circle

Libraries
Allowed: advapi32.dll, shell32.dll, user32.dll, kernel32.dll, version.dll, comctl32.dll, ole32.dll, gdi32.dll
hasLibs: True check_circle
Suspicious
hasAllowed: True check_circle
hasSuspicious: False cancel

Timestamp
Past: False cancel
Valid: True check_circle
Value: 2009-12-05 20:52:12
Future: False cancel

Compilation
Packed: True check_circle
Missing: False cancel
Packers: Nullsoft PiMP Stub -> SFX
Compiled: False cancel
Compilers

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.rsrc: 18

pushpopmath
.data: 1
.rsrc: 7

garbagebytes
.rsrc: 6

programcontrolflowchange
.rsrc: 6

cpuinstructionsresultscomparison
.rsrc: 1

AVclass
bitmin
1
VirusTotal
md5
2915b3f8b703eb744fc54c81f4a9c67f
sha1
e10361a11f8a7f232ac3cb2125c1875a0a69a3e4
SCANS (DETECTION RATE = 83.10%)
AVG
result: Win32:HarHarMiner-A [Trj]
update: 20191122
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=85)
update: 20191122
version: 2019.9.16.1
detected: True check_circle

APEX
result: Malicious
update: 20191122
version: 5.88
detected: True check_circle

Bkav
update: 20191121
version: 1.3.0.9899
detected: False cancel

K7GW
result: Trojan ( 004da88f1 )
update: 20191121
version: 11.79.32619
detected: True check_circle

ALYac
result: Worm.Generic.914973
update: 20191122
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:HarHarMiner-A [Trj]
update: 20191122
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Dropper.Gen
update: 20191122
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
result: W32/Trojan.ACHI-3157
update: 20191122
version: 6.2.2.2
detected: True check_circle

DrWeb
result: Trojan.MulDrop11.20247
update: 20191122
version: 7.0.42.9300
detected: True check_circle

GData
result: Win32.Application.CoinMiner.X
update: 20191122
version: A:25.24054B:26.16732
detected: True check_circle

Panda
result: Trj/CI.A
update: 20191121
version: 4.6.4.2
detected: True check_circle

VBA32
result: Trojan.Miner
update: 20191121
version: 4.2.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic.pak!cobra
update: 20191122
version: 79502
detected: True check_circle

Zoner
update: 20191121
version: 1.0.0.1
detected: False cancel

ClamAV
result: Win.Coinminer.Generic-7151253-0
update: 20191121
version: 0.102.1.0
detected: True check_circle

Comodo
result: Malware@#pnxmzj0etj1s
update: 20191122
version: 31751
detected: True check_circle

F-Prot
update: 20191122
version: 4.7.1.166
detected: False cancel

Ikarus
result: PUA.CoinMiner
update: 20191121
version: 0.1.5.2
detected: True check_circle

McAfee
result: Artemis!2915B3F8B703
update: 20191122
version: 6.0.6.653
detected: True check_circle

Rising
result: Downloader.Agent/NSIS!1.BF5B (CLASSIC:5:K8YINHa7zGB)
update: 20191121
version: 25.0.0.24
detected: True check_circle

Sophos
result: XMRig Miner (PUA)
update: 20191122
version: 4.98.0
detected: True check_circle

Yandex
result: Riskware.Agent!
update: 20191121
version: 5.5.2.24
detected: True check_circle

Zillya
result: Worm.BitMin.Win32.282
update: 20191121
version: 2.0.0.3956
detected: True check_circle

Acronis
result: suspicious
update: 20191119
version: 1.1.1.58
detected: True check_circle

Alibaba
result: Trojan:Win32/CoinMiner.ali1002002
update: 20190527
version: 0.3.0.5
detected: True check_circle

Arcabit
result: Worm.Generic.DDF61D
update: 20191122
version: 1.0.0.861
detected: True check_circle

Cylance
result: Unsafe
update: 20191122
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20190918
version: 3.0.15
detected: True check_circle

FireEye
result: Generic.mg.2915b3f8b703eb74
update: 20191122
version: 29.7.0.0
detected: True check_circle

TACHYON
update: 20191122
version: 2019-11-22.01
detected: False cancel

Tencent
update: 20191122
version: 1.0.0.1
detected: False cancel

ViRobot
result: Trojan.Win32.Z.Coinminer.2361084
update: 20191121
version: 2014.3.20.0
detected: True check_circle

Webroot
result: W32.Worm.NSIS.BitMin
update: 20191122
version: 1.0.0.403
detected: True check_circle

Ad-Aware
result: Worm.Generic.914973
update: 20191122
version: 3.0.5.370
detected: True check_circle

AegisLab
result: Worm.NSIS.BitMin.o!c
update: 20191116
version: 4.2
detected: True check_circle

Emsisoft
result: Worm.Generic.914973 (B)
update: 20191031
version: 2018.12.0.1641
detected: True check_circle

F-Secure
result: Trojan.TR/CoinMiner.tefca
update: 20191122
version: 12.0.86.52
detected: True check_circle

Fortinet
result: Riskware/CoinMiner
update: 20191122
version: 6.2.137.0
detected: True check_circle

Invincea
result: heuristic
update: 20190904
version: 6.3.6.26157
detected: True check_circle

Jiangmin
result: RiskTool.BitCoinMiner.lmv
update: 20191121
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20191122
version: 2013.8.14.323
detected: False cancel

Paloalto
update: 20191122
version: 1.0
detected: False cancel

Symantec
result: Trojan.Gen.MBT
update: 20191122
version: 1.11.0.0
detected: True check_circle

Trapmine
result: suspicious.low.ml.score
update: 20190826
version: 3.1.81.800
detected: True check_circle

AhnLab-V3
result: Worm/Win32.NeksMiner.C2438509
update: 20191122
version: 3.16.5.25880
detected: True check_circle

Antiy-AVL
result: Trojan/Win32.Miner
update: 20191122
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: Worm.NSIS.BitMin.d
update: 20191122
version: 15.0.1.13
detected: True check_circle

MaxSecure
result: Trojan.Malware.74620654.susgen
update: 20191121
version: 1.0.0.1
detected: True check_circle

Microsoft
result: PUA:Win32/CoinMiner
update: 20191122
version: 1.1.16500.1
detected: True check_circle

Qihoo-360
result: Win32/Worm.458
update: 20191122
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: Worm.NSIS.BitMin.d
update: 20191122
version: 1.0
detected: True check_circle

Cybereason
result: malicious.8b703e
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: NSIS/CoinMiner.AA
update: 20191122
version: 20388
detected: True check_circle

TrendMicro
result: Trojan.Win32.MALXMR.USASHJG19
update: 20191122
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: Worm.Generic.914973
update: 20191122
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_100% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan ( 004da88f1 )
update: 20191121
version: 11.79.32618
detected: True check_circle

SentinelOne
result: DFI - Suspicious PE
update: 20191118
version: 1.11.0.53
detected: True check_circle

Avast-Mobile
update: 20191121
version: 191121-00
detected: False cancel

Malwarebytes
result: Trojan.Agent.VBS
update: 20191122
version: 2.1.1.1115
detected: True check_circle

TotalDefense
update: 20191121
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Worm.Agent
update: 20191121
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.Miner.gedfqv
update: 20191122
version: 1.0.134.24859
detected: True check_circle

BitDefenderTheta
result: Gen:NN.ZexaF.32253.sN0@auTn2Api
update: 20191120
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: Worm.Generic.914973
update: 20191122
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20191115
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: BehavesLike.Win32.Downloader.vc
update: 20191121
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
result: Trojan.Win32.MALXMR.USASHJG19
update: 20191122
version: 10.0.0.1040
detected: True check_circle

total
71
sha256
9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
scan_id
9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507-1574396616
resource
2915b3f8b703eb744fc54c81f4a9c67f
positives
59
scan_date
2019-11-22 04:23:36
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\desktop.ini
22/11/2019 - 15:45:43.700Read1480C:\malware.exeC:\Users\desktop.ini
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:43.700Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:43.700Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:43.762Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:43.762Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:43.809Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.809Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.809Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:43.809Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:43.809Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:43.809Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:43.809Open1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:43.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:43.809Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:43.809Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:43.856Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.856Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.856Open1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:43.856Unknown1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:43.856Open1480C:\malware.exeC:\Monitor\Malware
22/11/2019 - 15:45:43.856Unknown1480C:\malware.exeC:\Monitor\Malware
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\System32\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\Windows\System32\propsys.dll
22/11/2019 - 15:45:43.903Open1480C:\malware.exeC:\
22/11/2019 - 15:45:43.903Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:43.950Open1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.950Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.950Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Read1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Read1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Read1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Read1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Read1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:43.997Unknown1480C:\malware.exeC:\malware.exe
22/11/2019 - 15:45:43.997Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\CRYPTSP.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\RpcRtRemote.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:45:44.200Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:45:44.200Open1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:45:44.200Unknown1480C:\malware.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:45:44.356Open1480C:\malware.exeC:\Windows\SysWOW64\mssprxy.dll
22/11/2019 - 15:45:44.356Open1480C:\malware.exeC:\Windows\SysWOW64\mssprxy.dll
22/11/2019 - 15:45:46.90Open1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:46.90Unknown1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:46.90Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.90Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot\Searches\desktop.ini
22/11/2019 - 15:45:46.184Read1480C:\malware.exeC:\Users\Behemot\Searches\desktop.ini
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot\Videos\desktop.ini
22/11/2019 - 15:45:46.184Read1480C:\malware.exeC:\Users\Behemot\Videos\desktop.ini
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot\Pictures\desktop.ini
22/11/2019 - 15:45:46.184Read1480C:\malware.exeC:\Users\Behemot\Pictures\desktop.ini
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot\Contacts\desktop.ini
22/11/2019 - 15:45:46.184Read1480C:\malware.exeC:\Users\Behemot\Contacts\desktop.ini
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.184Open1480C:\malware.exeC:\Users\Behemot\Favorites\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Favorites\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot\Music\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Music\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot\Downloads\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Downloads\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot\Documents\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Documents\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot\Links\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Links\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Users\Behemot\Saved Games\desktop.ini
22/11/2019 - 15:45:46.247Read1480C:\malware.exeC:\Users\Behemot\Saved Games\desktop.ini
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\apphelp.dll
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:45:46.247Open1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.247Unknown1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.262Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows
22/11/2019 - 15:45:46.262Unknown1480C:\malware.exeC:\Windows
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.262Unknown1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.262Unknown1480C:\malware.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.262Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Read1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Read1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.450Open1480C:\malware.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:46.622Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
22/11/2019 - 15:45:46.622Open1480C:\malware.exeC:\Windows\SysWOW64\shell32.dll
22/11/2019 - 15:45:46.622Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.622Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.622Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.622Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.622Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.622Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\urlmon.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\urlmon.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Secur32.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:46.715Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:46.715Open1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:46.731Unknown1480C:\malware.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:46.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe:Zone.Identifier
22/11/2019 - 15:45:46.731Open1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:46.731Unknown1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:46.731Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.731Write1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Unknown1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Read1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:46.778Open1480C:\malware.exeC:\Users\Behemot\AppData\Roaming\TempoRX\ui\SwDRM.dll
22/11/2019 - 15:45:46.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\Prefetch\VID001.EXE-61541490.pf
22/11/2019 - 15:45:46.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:45:46.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:45:46.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:45:46.918Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:45:46.918Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe.Local
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
22/11/2019 - 15:45:46.934Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VERSION.dll
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:45:46.934Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:45:46.997Unknown1480C:\malware.exeC:\Windows
22/11/2019 - 15:45:46.997Unknown1480C:\malware.exeC:\Monitor
22/11/2019 - 15:45:46.997Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
22/11/2019 - 15:45:46.997Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:47.59Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:45:47.59Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:45:47.59Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\uxtheme.dll
22/11/2019 - 15:45:47.59Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\uxtheme.dll
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\SHFOLDER.DLL
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shfolder.dll
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shfolder.dll
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:45:47.122Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shell32.dll
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe.Local
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:47.122Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
22/11/2019 - 15:45:47.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\WindowsShell.Manifest
22/11/2019 - 15:45:47.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\WindowsShell.ManifestWindowsShell.Manifest
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Desktop\desktop.ini
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Desktop\desktop.ini
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:47.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsv11CF.tmp
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsv11CF.tmp
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:45:47.137Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsv11CF.tmp
22/11/2019 - 15:45:47.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsv11CF.tmp
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.262Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.340Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.356Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.372Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.434Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost32.exe
22/11/2019 - 15:45:47.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.450Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.528Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.543Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.559Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.559Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:45:47.622Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:47.622Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:45:47.668Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:47.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.668Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Searches\desktop.ini
22/11/2019 - 15:45:47.684Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Searches\desktop.ini
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Videos\desktop.ini
22/11/2019 - 15:45:47.684Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Videos\desktop.ini
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Pictures\desktop.ini
22/11/2019 - 15:45:47.684Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Pictures\desktop.ini
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Contacts\desktop.ini
22/11/2019 - 15:45:47.684Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Contacts\desktop.ini
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Favorites\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Favorites\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Music\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Music\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Downloads\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Downloads\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Documents\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Documents\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Links\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Links\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Saved Games\desktop.ini
22/11/2019 - 15:45:47.747Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\Saved Games\desktop.ini
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\apphelp.dll
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:45:47.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.762Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shdocvw.dll
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shell32.dll
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\shell32.dll
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.778Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.778Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.778Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\LINKINFO.dll
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\linkinfo.dll
22/11/2019 - 15:45:47.778Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\linkinfo.dll
22/11/2019 - 15:45:48.75Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.75Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.75Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\ntshrui.dll
22/11/2019 - 15:45:48.75Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ntshrui.dll
22/11/2019 - 15:45:48.75Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ntshrui.dll
22/11/2019 - 15:45:48.418Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\srvcli.dll
22/11/2019 - 15:45:48.418Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:45:48.418Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:45:48.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\cscapi.dll
22/11/2019 - 15:45:48.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cscapi.dll
22/11/2019 - 15:45:48.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cscapi.dll
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\slc.dll
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\slc.dll
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\slc.dll
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:48.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:48.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:48.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk
22/11/2019 - 15:45:48.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu
22/11/2019 - 15:45:48.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:45:48.653Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.653Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:45:48.653Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.653Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.700Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:48.700Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\Fonts\sserife.fon
22/11/2019 - 15:45:48.700Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\dwmapi.dll
22/11/2019 - 15:45:48.700Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dwmapi.dll
22/11/2019 - 15:45:48.700Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dwmapi.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\Secur32.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:48.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:48.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:48.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dllapi-ms-win-downlevel-advapi32-l2-1-0.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winhttp.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winhttp.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\webio.dll
22/11/2019 - 15:45:48.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\webio.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\IPHLPAPI.DLL
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\WINNSI.DLL
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winnsi.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winnsi.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\api-ms-win-downlevel-shlwapi-l2-1-0.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
22/11/2019 - 15:45:48.950Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
22/11/2019 - 15:45:48.950Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dllapi-ms-win-downlevel-shlwapi-l2-1-0.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\DNSAPI.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dnsapi.dll
22/11/2019 - 15:45:48.950Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dnsapi.dll
22/11/2019 - 15:45:48.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mswsock.dll
22/11/2019 - 15:45:48.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mswsock.dll
22/11/2019 - 15:45:48.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wship6.dll
22/11/2019 - 15:45:48.997Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wship6.dll
22/11/2019 - 15:45:49.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\netprofm.dll
22/11/2019 - 15:45:49.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\netprofm.dll
22/11/2019 - 15:45:49.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\nlaapi.dll
22/11/2019 - 15:45:49.122Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\nlaapi.dll
22/11/2019 - 15:45:49.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\dhcpcsvc6.DLL
22/11/2019 - 15:45:49.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
22/11/2019 - 15:45:49.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
22/11/2019 - 15:45:49.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc6.dll
22/11/2019 - 15:45:49.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc6.dlldhcpcsvc6.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\CRYPTSP.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\RpcRtRemote.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:45:49.215Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:45:49.215Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:45:49.215Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
22/11/2019 - 15:45:49.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\History\History.IE5
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\dhcpcsvc.DLL
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc.dll
22/11/2019 - 15:45:49.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\dhcpcsvc.dll
22/11/2019 - 15:45:49.293Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\rasadhlp.dll
22/11/2019 - 15:45:49.293Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rasadhlp.dll
22/11/2019 - 15:45:49.293Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\rasadhlp.dll
22/11/2019 - 15:45:49.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\npmproxy.dll
22/11/2019 - 15:45:49.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\npmproxy.dll
22/11/2019 - 15:45:49.637Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
22/11/2019 - 15:45:49.637Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\FWPUCLNT.DLL
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wininet.dll
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe.Local
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:49.747Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
22/11/2019 - 15:45:49.747Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\WSHTCPIP.DLL
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wship6.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wship6.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wship6.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:49.762Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wshqos.dll
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:45:50.356Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:50.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:50.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:50.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:50.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:50.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx.exe
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:45:50.418Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:45:50.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wininet.dll
22/11/2019 - 15:45:50.653Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wininet.dll
22/11/2019 - 15:45:51.668Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\normidna.nls
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:45:54.137Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:45:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\javarx2.exe
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:46:54.137Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst1789.tmp
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:46:54.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\System32\propsys.dll
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.137Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.153Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.153Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\MPR.dll
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\drprov.dll
22/11/2019 - 15:46:54.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\drprov.dll
22/11/2019 - 15:46:54.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:54.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:54.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ntlanman.dll
22/11/2019 - 15:46:54.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ntlanman.dll
22/11/2019 - 15:46:54.309Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\davclnt.dll
22/11/2019 - 15:46:54.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\davclnt.dll
22/11/2019 - 15:46:54.637Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\davhlpr.dll
22/11/2019 - 15:46:54.684Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\davhlpr.dll
22/11/2019 - 15:46:54.965Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mssprxy.dll
22/11/2019 - 15:46:54.965Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\mssprxy.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\wkscli.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\netutils.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.12Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.28Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.43Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsd17BC.tmp\inetc.dll
22/11/2019 - 15:46:55.825Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHQ10TF8
22/11/2019 - 15:46:55.825Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHQ10TF8
22/11/2019 - 15:46:55.825Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHQ10TF8\tessrx[1].htm
22/11/2019 - 15:46:55.825Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHQ10TF8\tessrx[1].htmtessrx[1].htm
22/11/2019 - 15:46:55.825Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHQ10TF8\tessrx[1].htmtessrx[1].htm
22/11/2019 - 15:46:56.840Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:56.840Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:56.840Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe:Zone.Identifier
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:56.903Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:56.903Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe:Zone.Identifier
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:57.90Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:46:57.106Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:57.106Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:46:57.106Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.106Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.106Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.106Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.106Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.106Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.106Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:46:57.153Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.153Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.168Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.168Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.184Read2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.184Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.184Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.200Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.200Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.450Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.450Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.450Unknown1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:46:57.450Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:46:57.450Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:46:57.450Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.465Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.465Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.481Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.481Read2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.481Read2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.559Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:57.559Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.559Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:57.559Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:57.559Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:57.575Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:57.575Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:57.575Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:57.575Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:57.575Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:57.575Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Read2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Read2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.575Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:57.575Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:57.590Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:57.590Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.590Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.mui
22/11/2019 - 15:46:57.590Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:57.606Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.mui
22/11/2019 - 15:46:57.606Read2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.muitaskkill.exe.mui
22/11/2019 - 15:46:57.606Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.606Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.606Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:57.606Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.653Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:57.653Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:57.653Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:57.700Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:57.700Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:57.700Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:46:57.809Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.809Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.809Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.825Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.825Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.825Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:57.825Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:57.825Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:57.825Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:46:57.872Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:57.872Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:57.872Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:57.872Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:57.872Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:57.981Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:57.981Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:46:57.981Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:46:57.981Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:57.997Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:57.997Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
22/11/2019 - 15:46:57.997Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:46:57.997Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:46:59.465Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:46:59.465Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:46:59.465Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt-BR\wmiutils.dll.mui
22/11/2019 - 15:46:59.465Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt\wmiutils.dll.mui
22/11/2019 - 15:46:59.465Open1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.mui
22/11/2019 - 15:46:59.481Read1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
22/11/2019 - 15:46:59.481Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:46:59.481Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:46:59.481Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt-BR\wmiutils.dll.mui
22/11/2019 - 15:46:59.481Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt\wmiutils.dll.mui
22/11/2019 - 15:46:59.481Open2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.mui
22/11/2019 - 15:46:59.653Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.653Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.muitaskkill.exe.mui
22/11/2019 - 15:46:59.653Unknown1760C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.653Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.668Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.668Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.668Read2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.668Open2688C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:59.668Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
22/11/2019 - 15:46:59.668Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.668Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.668Unknown2712C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.715Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pfTASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pfTASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.715Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.715Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.715Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Read1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Open1408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.793Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.793Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\PV4CHTIY.TXT
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\6SGKN470.TXT
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\QSML[7].XML
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.809Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\6SGKN470.TXT
22/11/2019 - 15:46:59.809Read2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.809Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.825Read2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pfTASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Prefetch\TASKKILL.EXE-E0105477.pfTASKKILL.EXE-E0105477.pf
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Default\AppData\Roaming\Microsoft\Windows
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.825Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.825Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\PV4CHTIY.TXT
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\6SGKN470.TXT
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\QSML[7].XML
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:46:59.840Read2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\6SGKN470.TXT
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ole32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\Microsoft\Windows\Cookies\MFZB191A.txt
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.840Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.840Open2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\oleaut32.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ws2_32.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\nsi.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\shlwapi.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\clbcatq.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RCRTXD2\px[1]px[1]
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exe\Device\HarddiskVolume2
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.934Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.934Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.mui
22/11/2019 - 15:46:59.950Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:59.950Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:59.950Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\version.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\secur32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.950Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dll
22/11/2019 - 15:46:59.950Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\framedynos.dllframedynos.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wtsapi32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netapi32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\dbghelp.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.mui
22/11/2019 - 15:46:59.950Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.mui
22/11/2019 - 15:46:59.965Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:46:59.965Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rpcss.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:47:0.106Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:0.106Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:47:0.106Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:47:0.106Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:47:0.106Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemprox.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemcomn.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbemcomn.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:47:0.168Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\Logs
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\winsta.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:0.168Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\cryptsp.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\rsaenh.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:47:0.168Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:47:0.168Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dll
22/11/2019 - 15:47:0.168Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\RpcRtRemote.dllRpcRtRemote.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:47:0.231Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:47:0.278Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:47:0.278Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wbemsvc.dll
22/11/2019 - 15:47:0.309Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:47:0.309Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:47:0.309Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt-BR\wmiutils.dll.mui
22/11/2019 - 15:47:0.309Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt\wmiutils.dll.mui
22/11/2019 - 15:47:0.309Open2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.mui
22/11/2019 - 15:47:0.325Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:47:0.325Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\fastprox.dll
22/11/2019 - 15:47:0.325Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\NTDSAPI.dll
22/11/2019 - 15:47:0.325Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:47:0.325Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\ntdsapi.dll
22/11/2019 - 15:47:0.387Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:47:0.387Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\wmiutils.dll
22/11/2019 - 15:47:0.387Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt-BR\wmiutils.dll.mui
22/11/2019 - 15:47:0.387Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\pt\wmiutils.dll.mui
22/11/2019 - 15:47:0.387Open2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.mui
22/11/2019 - 15:47:0.575Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
22/11/2019 - 15:47:0.575Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:47:0.575Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:0.575Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.muitaskkill.exe.mui
22/11/2019 - 15:47:0.575Unknown2840C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:47:0.575Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:0.575Unknown2688C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:0.575Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\wbem\en-US\wmiutils.dll.muiwmiutils.dll.mui
22/11/2019 - 15:47:0.575Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows
22/11/2019 - 15:47:0.575Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:0.575Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\taskkill.exe.muitaskkill.exe.mui
22/11/2019 - 15:47:0.575Unknown2848C:\Windows\SysWOW64\taskkill.exeC:\Windows\SysWOW64\pt-BR\KernelBase.dll.muiKernelBase.dll.mui
22/11/2019 - 15:47:0.622Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:0.622Unknown1408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe:Zone.Identifier
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\AppPatch\AppPatch64\sysmain.sdb
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:1.137Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.137Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.184Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\Prefetch\UIHOST64.EXE-7F255FFA.pf
22/11/2019 - 15:47:1.184Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\sechost.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\sechost.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\IPHLPAPI.DLL
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\IPHLPAPI.DLL
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\IPHLPAPI.DLL
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\WINNSI.DLL
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\winnsi.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\winnsi.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.403Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\imm32.dll
22/11/2019 - 15:47:1.418Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\dhcpcsvc6.DLL
22/11/2019 - 15:47:1.418Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc6.dll
22/11/2019 - 15:47:1.418Unknown296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc6.dlldhcpcsvc6.dll
22/11/2019 - 15:47:1.418Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc6.dll
22/11/2019 - 15:47:1.418Unknown296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc6.dlldhcpcsvc6.dll
22/11/2019 - 15:47:1.512Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\dhcpcsvc.DLL
22/11/2019 - 15:47:1.512Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc.dll
22/11/2019 - 15:47:1.512Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dhcpcsvc.dll
22/11/2019 - 15:47:1.559Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\powrprof.dll
22/11/2019 - 15:47:1.559Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\powrprof.dll
22/11/2019 - 15:47:1.559Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\powrprof.dll
22/11/2019 - 15:47:1.559Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\uxtheme.dll
22/11/2019 - 15:47:1.559Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\uxtheme.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:1.606Unknown296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\mswsock.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\mswsock.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\WSHTCPIP.DLL
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\WSHTCPIP.DLL
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\WSHTCPIP.DLL
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\WSHTCPIP.DLL
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\WSHTCPIP.DLL
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wshqos.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:1.606Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\wship6.dll
22/11/2019 - 15:47:2.43Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\tzres.dll
22/11/2019 - 15:47:2.43Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\tzres.dll
22/11/2019 - 15:47:2.43Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\tzres.dll
22/11/2019 - 15:47:2.43Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\tzres.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\nlaapi.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\nlaapi.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\NapiNSP.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\NapiNSP.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\pnrpnsp.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\pnrpnsp.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\DNSAPI.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dnsapi.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\dnsapi.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\winrnr.dll
22/11/2019 - 15:47:2.75Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\winrnr.dll
22/11/2019 - 15:47:2.168Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\rasadhlp.dll
22/11/2019 - 15:47:2.168Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\rasadhlp.dll
22/11/2019 - 15:47:2.168Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\rasadhlp.dll
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe:Zone.Identifier
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.168Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:47:2.231Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\FWPUCLNT.DLL
22/11/2019 - 15:47:2.231Open296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Windows\System32\FWPUCLNT.DLL
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:2.231Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.231Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.231Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:2.247Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.247Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.247Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.481Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.481Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.481Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.497Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.497Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.512Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.512Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.512Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.512Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:47:2.512Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:2.637Read2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.637Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.637Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.653Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.653Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.668Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:2.668Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.668Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.731Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.872Unknown2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.872Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.872Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.872Read2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.872Read2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.887Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.903Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.903Unknown2408C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.903Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:2.903Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.918Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.918Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.918Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:2.918Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:2.918Read2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:2.918Read2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:2.918Open2408C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\Prefetch\NET.EXE-40D48057.pf
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows
22/11/2019 - 15:47:2.965Unknown2020C:\Windows\SysWOW64\net.exeC:\Windows
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\netutils.dll
22/11/2019 - 15:47:2.965Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\browcli.dll
22/11/2019 - 15:47:3.12Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\browcli.dll
22/11/2019 - 15:47:3.12Open1276C:\Windows\SysWOW64\find.exeC:\Windows\Prefetch\FIND.EXE-9AADDA11.pf
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows
22/11/2019 - 15:47:3.28Unknown1276C:\Windows\SysWOW64\find.exeC:\Windows
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\ulib.dll
22/11/2019 - 15:47:3.28Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\ulib.dll
22/11/2019 - 15:47:3.28Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\samcli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\samcli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\srvcli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\wkscli.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\mpr.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\IPHLPAPI.DLL
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\winnsi.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\winnsi.dll
22/11/2019 - 15:47:3.43Read2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open1276C:\Windows\SysWOW64\find.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\netmsg.dll
22/11/2019 - 15:47:3.43Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\netmsg.dll
22/11/2019 - 15:47:3.153Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\cscapi.dll
22/11/2019 - 15:47:3.153Open2020C:\Windows\SysWOW64\net.exeC:\Windows\SysWOW64\cscapi.dll
22/11/2019 - 15:47:4.590Read296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exeC:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:5.481Open1276C:\Windows\SysWOW64\find.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:5.481Unknown1276C:\Windows\SysWOW64\find.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:5.497Unknown2020C:\Windows\SysWOW64\net.exeC:\Windows
22/11/2019 - 15:47:5.497Unknown2020C:\Windows\SysWOW64\net.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.512Unknown1276C:\Windows\SysWOW64\find.exeC:\Windows
22/11/2019 - 15:47:5.512Unknown1276C:\Windows\SysWOW64\find.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.575Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.575Unknown2408C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.575Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.575Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:5.575Unknown260C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.575Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.575Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.575Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.590Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.590Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.590Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.590Read260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.590Open260C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ui\SwDRM.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:5.653Read596C:\Windows\SysWOW64\cmd.exeC:\Windows\Prefetch\CMD.EXE-AC113AA8.pfCMD.EXE-AC113AA8.pf
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:5.653Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:5.653Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nls
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\locale.nls
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\Globalization\Sorting\SortDefault.nlsSortDefault.nls
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\AppPatch\sysmain.sdb
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\BOOTSECT.EXE
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\Temp\TMP000000032EDF9B37C5E17B29
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\ntdll.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\kernel32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\kernel32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\user32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\ntdll.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\apisetschema.dllapisetschema.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\KernelBase.dllKernelBase.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msvcrt.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\user32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\gdi32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\lpk.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\usp10.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\advapi32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\rpcrt4.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sspicli.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cryptbase.dllcryptbase.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\msctf.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\apphelp.dll
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exe\Device\HarddiskVolume2
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64win.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64cpu.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\System32\wow64log.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.668Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\winbrand.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\sechost.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.668Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\imm32.dll
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:47:5.684Open596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.684Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.684Read596C:\Windows\SysWOW64\cmd.exeC:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.700Unknown596C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.700Unknown596C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:47:5.700Unknown260C:\Windows\SysWOW64\cmd.exeC:\Windows
22/11/2019 - 15:47:5.700Unknown260C:\Windows\SysWOW64\cmd.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:48:2.231Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nst2188.tmp
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:48:2.231Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.231Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.247Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.247Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.262Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.262Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.356Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:48:2.372Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:48:2.372Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Monitor\Files\DeletedFiles
22/11/2019 - 15:49:3.450Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp\nsi10AC.tmp
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Local\Temp
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:49:3.450Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\desktop.ini
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.450Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.450Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Read2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\VID001.exe
22/11/2019 - 15:49:3.465Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.465Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.481Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.481Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.497Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.497Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.575Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.590Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.590Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming\TempoRX
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\Users\Behemot\AppData\Roaming
22/11/2019 - 15:49:3.606Open2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\
22/11/2019 - 15:49:3.606Unknown2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeC:\

Process
Trace
22/11/2019 - 15:45:46.778Create1480C:\malware.exe2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe
22/11/2019 - 15:46:57.90Create2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe1408C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.90Create2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe2688C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:46:57.481Create2688C:\Windows\SysWOW64\cmd.exe1760C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:57.497Create1408C:\Windows\SysWOW64\cmd.exe2712C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.653Terminate2688C:\Windows\SysWOW64\cmd.exe1760C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.653Create2688C:\Windows\SysWOW64\cmd.exe2840C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.668Terminate1408C:\Windows\SysWOW64\cmd.exe2712C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:46:59.731Create1408C:\Windows\SysWOW64\cmd.exe2848C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.575Terminate2688C:\Windows\SysWOW64\cmd.exe2840C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.575Terminate2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe2688C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:0.575Terminate1408C:\Windows\SysWOW64\cmd.exe2848C:\Windows\SysWOW64\taskkill.exe
22/11/2019 - 15:47:0.622Terminate2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe1408C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:1.137Create2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe296C:\Users\Behemot\AppData\Roaming\TempoRX\uihost64.exe
22/11/2019 - 15:47:2.168Create2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe260C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.497Create260C:\Windows\SysWOW64\cmd.exe2408C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:2.872Create2408C:\Windows\SysWOW64\cmd.exe2020C:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:2.903Create2408C:\Windows\SysWOW64\cmd.exe1276C:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:5.497Terminate2408C:\Windows\SysWOW64\cmd.exe2020C:\Windows\SysWOW64\net.exe
22/11/2019 - 15:47:5.497Terminate2408C:\Windows\SysWOW64\cmd.exe1276C:\Windows\SysWOW64\find.exe
22/11/2019 - 15:47:5.575Terminate260C:\Windows\SysWOW64\cmd.exe2408C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.575Create260C:\Windows\SysWOW64\cmd.exe596C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.700Terminate260C:\Windows\SysWOW64\cmd.exe596C:\Windows\SysWOW64\cmd.exe
22/11/2019 - 15:47:5.700Terminate2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe260C:\Windows\SysWOW64\cmd.exe

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
22/11/2019 - 15:45:46.715Write1480C:\malware.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Run
22/11/2019 - 15:45:47.622Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exe\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
22/11/2019 - 15:45:48.950Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyEnable
22/11/2019 - 15:45:48.950Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyServer
22/11/2019 - 15:45:48.950Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProxyOverride
22/11/2019 - 15:45:48.950Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoConfigURL
22/11/2019 - 15:45:48.950Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsAutoDetect
22/11/2019 - 15:45:48.950Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsSavedLegacySettings
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapProxyBypass
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapIntranetName
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapUNCAsIntranet
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapAutoDetect
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\ContentCachePrefix
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\CookiesCachePrefix
22/11/2019 - 15:45:49.231Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\HistoryCachePrefix
22/11/2019 - 15:45:49.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:49.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:49.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:49.356Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
22/11/2019 - 15:45:50.512Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:50.512Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:50.512Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:50.512Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDecision
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadNetworkName
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{D8C667F4-C62D-460A-82E2-EC8687C3DC60}WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionReason
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecisionTime
22/11/2019 - 15:45:50.856Write2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDecision
22/11/2019 - 15:45:50.856Delete2172C:\Users\Behemot\AppData\Roaming\TempoRX\VID001.exeHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-83-08-f3WpadDetectedUrl

File Summary
Created
Identified: True check_circle

Deleted
Identified: True check_circle

Process Summary
Created
Identified: True check_circle

Deleted
Identified: True check_circle

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: True check_circle

Deleted
Identified: True check_circle

Browsers
Identified: False cancel

Internet
Identified: True check_circle

Loading...

DNS
Query
computer localhost arrow_forward computer gateway:DNS code zc�p.ru.
computer localhost arrow_forward computer gateway:51595 code dns.msftncsi.com.
computer localhost arrow_forward computer gateway:50043 code xmr-eu2.nanopool.org.
computer localhost arrow_forward computer gateway:DNS code xmr-eu2.nanopool.org.
computer localhost arrow_forward computer gateway:DNS code kr1s.ru.
computer localhost arrow_forward computer gateway:DNS code zcop.ru.
computer localhost arrow_forward computer gateway:50273 code kr1s.ru.
computer localhost arrow_forward computer gateway:59829 code zc�p.ru.
computer localhost arrow_forward computer gateway:49551 code dns.msftncsi.com.
computer localhost arrow_forward computer gateway:DNS code dns.msftncsi.com.

Response
computer gateway:DNS arrow_forward computer localhost code dns.msftncsi.com. reply_all 131.107.255.255

computer gateway:DNS arrow_forward computer localhost code xmr-eu2.nanopool.org. reply_all 51.255.34.80

computer gateway:DNS arrow_forward computer localhost code kr1s.ru. reply_all 185.26.112.217

computer gateway:DNS arrow_forward computer localhost code zcop.ru. reply_all 89.111.177.173


TCP
Info
51.15.55.100:14444 arrow_forward computer localhost:65194
computer localhost:65192 arrow_forward 89.111.177.173:80
computer localhost:65191 arrow_forward 185.26.112.217:80
185.26.112.217:80 arrow_forward computer localhost:65191
computer localhost:65194 arrow_forward 51.15.55.100:14444
computer localhost:65193 arrow_forward 185.26.112.217:80
185.26.112.217:80 arrow_forward computer localhost:65193
89.111.177.173:80 arrow_forward computer localhost:65192

UDP
Info
computer localhost:51595 arrow_forward computer localhost:53
computer localhost:49551 arrow_forward computer localhost:53
computer localhost:55394 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:59829
computer localhost:53 arrow_forward computer localhost:51595
computer localhost:53 arrow_forward computer localhost:49551
computer localhost:50273 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:50043
computer localhost:53 arrow_forward computer localhost:50273
computer localhost:50043 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:55394
computer localhost:59829 arrow_forward computer localhost:53
computer localhost:67 arrow_forward computer localhost:68
computer localhost:68 arrow_forward help_outline 255.255.255.255:67

HTTP
Info
computer localhost send GET kr1s.ru attach_file /tessrx.html
computer localhost send GET zcop.ru attach_file /javarx2.dat
computer localhost send GET kr1s.ru attach_file /javarx.dat

Summary
DNS
True check_circle

TCP
True check_circle

UDP
True check_circle

HTTP
True check_circle

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: False cancel

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 96.05%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 59.15%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 79.00%
suspicious: False cancel

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 63.44%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 98.80%
suspicious: True check_circle

Add to Collection
Download